Joey / Eat private release candidate
Implemented and verified private, unofficial Joey and Eat restaurant-directory source checkpoints without deploying or changing any live Cloudflare state.
Scope
- Host:
rdmsm4x - Project: Amagansett platform
- Isolated worktree:
/Users/richh/dev/_handoff/codex-out/amagansett-joey-eat-20260828 - Branch:
codex/joey-eat-curated-20260828 - Base:
ab8d0bbc0583bd6ffa0975163f5398708a9ad26d - Implementation commit:
a3e80252ee356f5595f95c24936bd9fbcf88dbe5 - Documentation commit:
23cce062864ed29bc6e3995807cb0f78002d6a50
Changes
- Added canonical venue/location reconciliation, completion fields, and deterministic sorting.
- Added 39 curated physical-location records from 36 normalized requests; 37 complete and two explicitly pending.
- Added Joey curated-only and Eat 811-location directory views, shared renderer/styles, and strict static-edge Workers/configurations.
- Added additive local-only D1 curation/identity schema, source/menu provenance, lawful photo states, and comprehensive tests.
- Added release receipt, identity provenance, machine reconciliation, report, and append-only session/issues milestones.
Exact project files are enumerated by commits
a3e80252ee356f5595f95c24936bd9fbcf88dbe5 and
23cce062864ed29bc6e3995807cb0f78002d6a50. No file in the
canonical checkout or any sibling worktree was changed.
Commands and verification
npm ciCI=1 npm run verify- Focused Vitest and Joey/Eat Playwright runs
- Joey/Eat Wrangler dry runs
- Fresh local D1 migrations apply/reapply through
0010 - Local SQLite integrity/count query
- Cookie-free boundary HTTP probes and Joey/Eat DNS probes
git diff --checkand bounded secret-pattern scan
Fresh post-commit verification passed 29 Vitest files / 193 tests,
strict TypeScript, six builds, platform/Preview/Joey/Eat Worker checks,
30 existing browser scenarios, and four Joey/Eat
desktop/mobile/accessibility scenarios. Local SQLite integrity was
ok, all 816 existing businesses remained, and new additive
tables were empty as designed.
Live state and blocker
No Worker, route, DNS, Access, or remote D1 mutation occurred. Guide, Forst, Preview, and API still redirect anonymous requests to Access; AK remains owner-authorized public read-only; invalid Share remains 404. Joey and Eat have no DNS records.
Deployment is blocked because the available Wrangler OAuth authorization cannot inspect or configure Cloudflare Access applications/policies for the new hostnames. An authorized operator must establish and prove per-host private Access before route creation, then verify anonymous denial and authenticated acceptance.
Undo
No live rollback is required. To remove the source checkpoint,
discard the isolated branch/worktree after preserving the commits. The
clean source anchor is
ab8d0bbc0583bd6ffa0975163f5398708a9ad26d. Do not use
destructive Git operations in the canonical checkout.
Outstanding owner action
Decide whether to authorize a Cloudflare operator with Access
application/policy capability. If authorized, follow the staged release
gate in docs/JOEY-EAT-CURATED-RECEIPT-20260828.md; do not
expose either hostname before anonymous denial is proven.