Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260910-1904-cvedb-google-auth-and-privacy

CVEDB now requires owner-only Google sign-in and uses a generic API URL; public personal Worker URLs are disabled.

Host scope: rdmsm4x. Canonical handoff files and authenticated Cloudflare operations executed here over SSH; Apple Notes requires an Aqua session.

CVEDB privacy remediation — 2026-09-10

Live result: cvedb.io requires Google sign-in through Cloudflare Access, with the existing owner-only Google policy. The active public-facing Worker is named cvedb and the API base is https://cvedb.io/v1. The old personal Workers hostname is disabled.

Changes

Verification

13 security tests pass on both rdmpw3275m and rdmsm4x. Coverage includes valid signed tokens as a positive control; expired, forged, unsigned, malformed, wrong-issuer and wrong-audience tokens; unknown hosts and missing configuration; authentication before backend access; the API route allowlist; legacy private endpoints returning 404 without touching storage; and sanitized API documentation.

26 live deployment checks pass. Cloudflare-downloaded module bytes match the retained source exactly. The original pre-change HTML is a positive control for the personal-reference scanner. All four Access policies were re-read and remain Google-only and owner-only. The database/secret bindings and ingestion schedules match their saved baseline. Both site routes point to cvedb.

Anonymous request Verified result
Main site and www HTTP 302 to Cloudflare Access
API status, docs and old email-auth path HTTP 302 to Cloudflare Access
Pages production alias and its saved-data path HTTP 302 to Cloudflare Access
Existing immutable Pages deployment alias HTTP 302 to Cloudflare Access
Old API workers.dev endpoint HTTP 404
New gateway workers.dev endpoint HTTP 404

The authenticated in-app browser loaded live CVE statistics and Explore results, opened a CVE detail page, and displayed the sanitized API reference with the generic URL. Its existing SSO session was accepted; a fresh interactive Google account challenge was not required. The browser blocked direct navigation to the JSON OpenAPI document, so its content was validated through the deployed module and backend tests instead.

The D1 tables app_user, watchlist, and watch_item each had 0 records at inspection. Legacy user_data, sessions, and auth_tokens tables were absent from the table inventory. This is a bounded inventory of the active database, not a claim that no private material exists anywhere. Browser-local inventory and report caches were not read, overwritten or deleted. Historical Pages deployments are protected by Access and retained for recovery; they are not claimed to have been rewritten.

Operational impact

Old clients calling the disabled personal Workers endpoint now receive 404. They must use the new API base with an authenticated Access session. Legacy email-link authentication and account/sync endpoints are intentionally unavailable. The Google allow policy uses the existing owner account; it does not grant access to every Gmail user.

Durable record and recovery

Application recovery can restore the saved backend source and route mappings through the recorded API operations. Keep Google Access and disabled direct Worker URLs in place during recovery. Restoring the old public access model would reintroduce the exposure and is not a routine rollback.

The live project source was recovered from Cloudflare because the indexed sites/cvedb.io repository is a historical design archive and the old deployment directories contain no current source. This task kept implementation in its own canonical handoff workspace rather than editing a shared live repository. A project-index entry and source-integration handoff are included for the canonical lead.

Apple Notes: the rdmsm4x entry remains pending because the execution session reports Background; the Markdown changelog is retained in that host's canonical archive. Local orchestration notes are recorded separately for rdmpw3275m when its Notes service is available.