CVEDB now requires owner-only Google sign-in and uses a generic API URL; public personal Worker URLs are disabled.
Host scope: rdmsm4x. Canonical handoff files and authenticated Cloudflare operations executed here over SSH; Apple Notes requires an Aqua session.
CVEDB privacy remediation — 2026-09-10
Live result: cvedb.io requires Google sign-in through Cloudflare Access, with the existing owner-only Google policy. The active public-facing Worker is named cvedb and the API base is https://cvedb.io/v1. The old personal Workers hostname is disabled.
Changes
- Created Google-only, owner-only Access applications covering
cvedb.io,*.cvedb.io,cvedb.pages.dev, and*.cvedb.pages.dev, with 24-hour sessions. Existing Google identity-provider configuration was reused. No new Google credentials were needed. - Deployed the generic
cvedbWorker for the apex and www routes. It verifies signed Access JWTs, including signature, issuer, audience, expiry and applicable time claims. The frontend and API share one origin. - Preserved the
cvedb-apiWorker as an internal backend through a service binding. Disabled its workers.dev URL and preview URLs. The newcvedbWorker also has both types of direct URL disabled. The account-wide workers.dev namespace is shared by unrelated services and was left unchanged. - Removed the personal API hostname from the active frontend, API
documentation, examples and OpenAPI document. Updated misleading
public/no-sign-in copy and added a sign-out link. CLI examples now use
authenticated
cloudflared access curlrequests. - Closed legacy account, registration, saved-data, billing and email-auth endpoints. Removed the unsafe fallback that returned a sign-in link directly when email delivery was unavailable. The gateway exposes only the CVE read routes and same-origin inventory matching.
- Responses from the gateway carry private/no-store cache controls, no-referrer and no-index directives, and do not expose wildcard CORS permissions.
- Preserved the D1 binding, backend secret bindings and both ingestion schedules. No credentials were rotated or copied between hosts, and no database rows were deleted.
Verification
13 security tests pass on both rdmpw3275m and rdmsm4x. Coverage includes valid signed tokens as a positive control; expired, forged, unsigned, malformed, wrong-issuer and wrong-audience tokens; unknown hosts and missing configuration; authentication before backend access; the API route allowlist; legacy private endpoints returning 404 without touching storage; and sanitized API documentation.
26 live deployment checks pass.
Cloudflare-downloaded module bytes match the retained source exactly.
The original pre-change HTML is a positive control for the
personal-reference scanner. All four Access policies were re-read and
remain Google-only and owner-only. The database/secret bindings and
ingestion schedules match their saved baseline. Both site routes point
to cvedb.
| Anonymous request | Verified result |
|---|---|
| Main site and www | HTTP 302 to Cloudflare Access |
| API status, docs and old email-auth path | HTTP 302 to Cloudflare Access |
| Pages production alias and its saved-data path | HTTP 302 to Cloudflare Access |
| Existing immutable Pages deployment alias | HTTP 302 to Cloudflare Access |
| Old API workers.dev endpoint | HTTP 404 |
| New gateway workers.dev endpoint | HTTP 404 |
The authenticated in-app browser loaded live CVE statistics and Explore results, opened a CVE detail page, and displayed the sanitized API reference with the generic URL. Its existing SSO session was accepted; a fresh interactive Google account challenge was not required. The browser blocked direct navigation to the JSON OpenAPI document, so its content was validated through the deployed module and backend tests instead.
The D1 tables app_user, watchlist, and
watch_item each had 0 records at
inspection. Legacy user_data, sessions, and
auth_tokens tables were absent from the table inventory.
This is a bounded inventory of the active database, not a claim that no
private material exists anywhere. Browser-local inventory and report
caches were not read, overwritten or deleted. Historical Pages
deployments are protected by Access and retained for recovery; they are
not claimed to have been rewritten.
Operational impact
Old clients calling the disabled personal Workers endpoint now receive 404. They must use the new API base with an authenticated Access session. Legacy email-link authentication and account/sync endpoints are intentionally unavailable. The Google allow policy uses the existing owner account; it does not grant access to every Gmail user.
Durable record and recovery
- Ticket: SEC-20260910-02.
- Canonical handoff:
rdmsm4x:/Users/richh/dev/_handoff/cvedb-privacy-20260910/. - Active source:
edge.mjs,site.mjs,api-sanitized.mjs. - Verification:
security.test.mjs,security-tests.txt,verify.py,verification.log,verification.json,private-record-counts.json. - Control-plane operations:
cf_inspect.py,protect.py,deploy.py,access-created.json,deployed.json. - Restricted rollback baseline:
backup/, containing the original backend response/source/settings, Pages configuration, routes, DNS records and schedules. Existing secret values are never exported; deployment preserves bindings in Cloudflare. - Reproduce security tests from the handoff directory:
node --test security.test.mjs. - Reproduce live checks from the handoff directory on rdmsm4x:
python3 verify.py. It reads Cloudflare credential names from the host-local approved secret store and never prints their values.
Application recovery can restore the saved backend source and route mappings through the recorded API operations. Keep Google Access and disabled direct Worker URLs in place during recovery. Restoring the old public access model would reintroduce the exposure and is not a routine rollback.
The live project source was recovered from Cloudflare because the
indexed sites/cvedb.io repository is a historical design
archive and the old deployment directories contain no current source.
This task kept implementation in its own canonical handoff workspace
rather than editing a shared live repository. A project-index entry and
source-integration handoff are included for the canonical lead.
Apple Notes: the rdmsm4x entry remains pending because the execution
session reports Background; the Markdown changelog is
retained in that host's canonical archive. Local orchestration notes are
recorded separately for rdmpw3275m when its Notes service is
available.