Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260827-1739-amagansett-ak-public-read-deployed

rdmsm4x-changelog-20260827-1739-amagansett-ak-public-read-deployed

Restored the public read-only homes feed on ak.amagansett.app by deploying only the prepared AK edge repair; anonymous listing reads now work while owner data, mutations, operational routes, and the other Amagansett privacy boundaries remain protected.

Scope

No shared API, D1, DNS, Cloudflare Access, Guide, Forst, Preview, Share, Pages, Zaraz, Google Analytics, or Search Console configuration was changed by this deployment.

Files changed

The canonical checkout and every preserved handoff worktree were retained. Nothing was merged, deleted, overwritten, or force-pushed.

Deployment command

Cloudflare credentials were loaded at runtime from the existing secret store by variable name; no value was printed or written into documentation.

npx wrangler deploy --config deploy/ak.wrangler.jsonc --strict --message "Restore isolated public AK listing reads from 9172852"

Wrangler 4.125.0 subsequently reported deployment message Restore isolated public AK listing reads from 9172852 with version fc17cd8b-e2df-4e59-8de3-6967fa6633a8 at 100%.

Security behavior shipped

The edge accepts anonymous production GETs only for feed, listing detail, properties, nearby places, routes, search suggestions, and the isolated public profile. It overwrites any caller-supplied identity with [email protected] before the protected service binding is called.

The edge rejects profile writes, reactions, subscriptions, digest previews, job status, inventory additions, share creation, the production resolver, and every other non-allowlisted platform operation before the service binding. Local loopback test behavior remains unchanged.

Verification evidence

Pre-deployment verification:

Fresh unauthenticated production acceptance:

Private documentation acceptance:

Two reporting-only shell variable-name issues occurred: one zsh loop temporarily used path, shadowing zsh's $path/PATH and causing jq: command not found while printing already-saved response bodies; a later acceptance loop used zsh's read-only status parameter and stopped before its first request. Both checks were rerun with non-reserved names and absolute command paths; no deployment, HTTP result, or data mutation was affected.

Rollback and undo

Durable Notes record

Outstanding owner actions