rdmsm4x-changelog-20260827-1745-amagansett-ak-public-read-deployed
Restored the public read-only homes feed on
ak.amagansett.app by deploying only the prepared AK edge
repair; anonymous listing reads now work while owner data, mutations,
operational routes, and the other Amagansett privacy boundaries remain
protected.
Scope
- Host:
rdmsm4x - Canonical project root preserved read-only:
/Users/richh/dev/sites/amagansett-app - Implementation worktree:
/Users/richh/dev/_handoff/codex-out/amagansett-ak-public-read-20260827 - Branch:
codex/amagansett-ak-public-read-20260827 - Deployed source commit:
9172852bfc4e3cdd8242e130ea1939d19f5fd942 - Documentation-only successor commit:
4d0b05064e4f667cfbc477944069de9537b9060f - Active AK Worker version:
fc17cd8b-e2df-4e59-8de3-6967fa6633a8at 100% - Previous and rollback AK Worker version:
4ef2dcbf-b59d-440f-b95a-fcc95561fbc9
No shared API, D1, DNS, Cloudflare Access, Guide, Forst, Preview, Share, Pages, Zaraz, Google Analytics, or Search Console configuration was changed by this deployment.
Files changed
- Implementation commit
9172852bfc4e3cdd8242e130ea1939d19f5fd942:/Users/richh/dev/_handoff/codex-out/amagansett-ak-public-read-20260827/workers/amagansett-ak-edge/src/index.ts/Users/richh/dev/_handoff/codex-out/amagansett-ak-public-read-20260827/tests/unit/ak-edge.test.ts/Users/richh/dev/_handoff/codex-out/amagansett-ak-public-read-20260827/docs/AK-PUBLIC-READ-REPAIR.md
- Deployment receipt update:
/Users/richh/dev/_handoff/codex-out/amagansett-ak-public-read-20260827/docs/AK-PUBLIC-READ-REPAIR.md/Users/richh/dev/_handoff/codex-out/amagansett-zaraz-ga4-handoff-20260827/README.md/Users/richh/dataroo.net/wiki/amagansett/ak-public-read-repair-2026-08-27.html/Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-amagansett-ak-public-read-20260827.json- this changelog
The canonical checkout and every preserved handoff worktree were retained. Nothing was merged, deleted, overwritten, or force-pushed.
Deployment command
Cloudflare credentials were loaded at runtime from the existing secret store by variable name; no value was printed or written into documentation.
npx wrangler deploy --config deploy/ak.wrangler.jsonc --strict --message "Restore isolated public AK listing reads from 9172852"
Wrangler 4.125.0 subsequently reported deployment message
Restore isolated public AK listing reads from 9172852 with
version fc17cd8b-e2df-4e59-8de3-6967fa6633a8 at 100%.
Security behavior shipped
The edge accepts anonymous production GETs only for feed, listing
detail, properties, nearby places, routes, search suggestions, and the
isolated public profile. It overwrites any caller-supplied identity with
public-ak-viewer@amagansett.invalid before the protected
service binding is called.
The edge rejects profile writes, reactions, subscriptions, digest previews, job status, inventory additions, share creation, the production resolver, and every other non-allowlisted platform operation before the service binding. Local loopback test behavior remains unchanged.
Verification evidence
Pre-deployment verification:
- focused AK tests: 12/12 passed;
- full repository verification: 26 Vitest files / 181 tests passed;
- strict TypeScript passed;
- Guide, AK, Forst, and Preview builds passed;
- Worker contracts and Wrangler dry-runs passed;
- 30 Playwright scenarios passed;
- worktree was clean before deployment.
Fresh unauthenticated production acceptance:
- feed, profile, properties, search suggestions, detail, nearby, and routes returned HTTP 200;
- the feed contained exactly 20 listing cards and
60 Alewive Brook Roadwas first; - the public profile returned zero signals and empty learned weights;
- subscription, digest, jobs, profile PUT, reaction PUT, inventory
POST, share POST, and resolver POST each returned HTTP 403 with
{"error":"Public AK is read-only"}; - the feed retained no-store caching, noindex/noarchive, no-referrer, nosniff, and restrictive CSP headers;
- the in-app browser rendered 20 listings, expanded the first property, displayed 24 remote source-linked photos, and showed no offline/backend/profile errors or console errors;
amagansett.app,forst.amagansett.app,preview.amagansett.app,api.amagansett.app, andamagansett-ak.pages.devcontinued to redirect to Cloudflare Access;- an invalid
share.amagansett.appcapability token remained HTTP 404.
Private documentation acceptance:
http://127.0.0.1:8787/amagansett/ak-public-read-repair-2026-08-27.htmlreturned HTTP 200 from the mounted origin;- after the standard dev.dataroo.net navigation/export publisher
completed, the served body exactly matched
/Users/richh/dataroo.net/wiki/amagansett/ak-public-read-repair-2026-08-27.htmlat SHA-256feba5b7332c5c5c4d9d03971caff8a955f862a44332a14416b768d7ebe25d292; https://dev.dataroo.net/amagansett/ak-public-read-repair-2026-08-27.htmlreturned HTTP 401 without credentials, preserving the private wiki boundary;dataroo-wiki-server-1anddataroo-auth_proxy-1remained healthy, anddataroo-cloudflared-1remained running.
Two reporting-only shell variable-name issues occurred: one zsh loop
temporarily used path, shadowing zsh's
$path/PATH and causing
jq: command not found while printing already-saved response
bodies; a later acceptance loop used zsh's read-only status
parameter and stopped before its first request. Both checks were rerun
with non-reserved names and absolute command paths; no deployment, HTTP
result, or data mutation was affected.
Rollback and undo
- Worker rollback: restore AK Worker version
4ef2dcbf-b59d-440f-b95a-fcc95561fbc9. This restores the pre-repair anonymous feed 403 behavior; it does not recreate the deleted AK Access application. - Source rollback: revert implementation commit
9172852bfc4e3cdd8242e130ea1939d19f5fd942only in a new authorized integration lane; do not rewrite the preserved branch history. - Documentation rollback: revert documentation-only commit
4d0b05064e4f667cfbc477944069de9537b9060fand restore the prior external handoff, Dataroo page, and PROJECTS.md line from version control or their previous recorded hashes. - Access rollback is separate: recreate the deleted AK self-hosted Access application and verify an unauthenticated redirect before declaring AK private again.
Durable Notes record
- The fleet helper successfully filed the changelog in its current
shared
llmlogdestination. - The controlling coordination policy still requires a per-host
record, so an additional exact-title note was filed in Apple Notes
folder
rdmsm4xasrdmsm4x-changelog-20260827-1745-amagansett-ak-public-read-deployed. - A same-title archive copy is retained at
/Users/richh/dev/LLM/Claude/changelogs/rdmsm4x-changelog-20260827-1745-amagansett-ak-public-read-deployed.md. - The shared
llmlogcopy was preserved rather than deleted.
Outstanding owner actions
- No action is required for the AK homes-feed incident; it is fixed and verified.
- Google Analytics receipt in GA4 Realtime/DebugView, effective Zaraz hostname behavior, capability-share analytics policy, and Google Search Console remain separately tracked work.