See
docs/specs/glossary.mdfor Burrow, Client, and Relay vocabulary. Owns the account application's security checks. Defers identity behavior todocs/specs/hosted.mdand terminal access todocs/specs/remote-security-model.md. Readdocs/specs/security.mdfirst; provisioning and real-provider acceptance are pending.
- FAIL IF Hosted accepts a request URL outside configured
APP_ORIGIN, grants marketing-origin credentialed CORS, or permits a state-changing auth request without exact Origin and CSRF checks; inspecthosted/server/worker-app.tsand the packed adapter. - FAIL IF authentication cookies have a Domain attribute, lack
__Host-, Secure, HttpOnly, or Path=/ in HTTPS, or session tokens appear in browser JSON or persistent browser storage; inspect the adapter andhosted/src/api.ts. - FAIL IF the production HTML permits third-party scripts, framing, inline script execution, or any worker (
worker-src 'none'origin-wide), any response but a 101 WebSocket upgrade bypassessecureHeadersincluding a misconfigured deployment's error, or anything but a content-hashed file under/assets/or/connect/assets/is cacheable, the SPA fallback's shell included; inspectsecureHeadersinhosted/server/headers.ts, binding resolution inhosted/server/worker-app.ts, and asset routing inhosted/wrangler.jsonc. - FAIL IF marketing scripts, analytics, provider avatars, or remote fonts enter the Hosted frontend; inspect the frontend import graph and deployed response when available.
Pinned by hosted/server/tests/workers.test.ts.
- FAIL IF the consumer changes
authPolicyaway from explicit linking or multiple independent logins, or accepts an explicit connection callback after its initiating login was revoked; inspecthosted/server/policy.tsand the packed adapter. - FAIL IF an unused provider credential enables login, an unknown provider name is accepted, or incomplete enabled credentials silently degrade; inspect
providerBindingsinhosted/server/policy.ts. - FAIL IF a managed-voice route admits any account but the verified
ADMIN_EMAILwithout rechecking per request, stores a voice token other than as its SHA-256, logs speak text, forwards an ElevenLabs body or status, or lets a binding or request field choose the upstream URL; inspecthosted/server/admin.tsandhosted/server/voice.ts. - FAIL IF Hosted account login mints a Burrow ACL grant or substitutes for the existing encrypted pairing/presence proof. The one-time rendezvous carries only handshake ciphertext and authorizes nothing; the ends' handshake and the laptop's confirmation do.
Pinned by hosted/server/tests/workers.test.ts and hosted/server/tests/policy.test.ts.
The one-time room is a counter with two sockets: docs/specs/one-time.md -> "Hosted rendezvous" owns its routes and lifecycle, and "Phone page" the page beside them; these are the checks on them.
- FAIL IF
OneTimeRoominhosted/server/one-time-room.tsparses, decodes, stores, or logs a forwarded frame; it bounds one by raw length and count alone.scripts/e2e-lint.mjsholds it textually. - FAIL IF a binary frame, one longer than
MAX_ONE_TIME_FRAME_LENGTH, or one pastMAX_ONE_TIME_FORWARDEDis forwarded rather than closing both ends with 4015, the count omits a frame the room received, or either bound is redeclared rather than imported fromremote-lib-common. - FAIL IF a second phone can join: the join must read and set
joinedwith no await between, in the Burrow socket's hibernation attachment rather than memory. - FAIL IF a room can outlive
expiresAt + ONE_TIME_EXPIRY_GRACE_MS, or admit a phone afterexpiresAt: the alarm is set before the Burrow socket is accepted, and closes every socket. - FAIL IF the Burrow route admits a request carrying any
Originheader, or the client route anOriginother than exactlyAPP_ORIGIN; inspectoneTimeRoutesinhosted/server/one-time.ts. - FAIL IF a room id comes from anything but 16 fresh random bytes the Worker mints per Burrow socket, the Burrow route takes a room from the request, or a room opens twice.
- FAIL IF either route reaches the room before its per-address rate limit (
cf-connecting-ip, IPv6 by /64, IPv4-mapped IPv6 by its IPv4), or a production rate-limitnamespace_idreachesPREVIEW_RATELIMIT_OFFSETinhosted/scripts/preview.mjs. - FAIL IF a one-time route or the room reads a cookie, reaches Hyperdrive or auth, mounts ahead of the 421 gate, or hands the room any header of the caller's but the upgrade.
- FAIL IF the
/connect/page's policy admits a source outsideAPP_ORIGIN's/connect/, a script outside/connect/assets/, or a connection but the client route; permits inline or off-origin script, framing, forms, or popups; or takes anAPP_ORIGINthat is not exactly an origin. InspectcontentSecurityPolicyinhosted/server/headers.ts. - FAIL IF a path under
/connect/is served but the page and its hashed assets, a missing asset gets the SPA shell, or a shell failingassertPocketShell's one-time mode can ship;build:one-timeinlib/package.jsonandstageOneTimeinhosted/scripts/stage-one-time.mjseach run it. InspectoneTimePageRoutesinhosted/server/one-time.ts.
scripts/e2e-lint.mjs also holds hosted/server/ to the Relay's absences: no protocol-v1 type, no direct-path signal or SDP, no ICE server (docs/specs/security-remote.md -> "Direct path"). Pinned by hosted/server/tests/one-time.test.ts, hosted/scripts/stage-one-time.test.mjs, lib/src/remote/pocket-app/assert-pocket-worker.test.ts, and hosted/scripts/production.test.mjs.
Must depend on a released pgstencil whose installed dist/provenance.json names a commit on pgstencil main with a passing security-audit. The core and auth packages must name the same clean commit.
-
FAIL IF a production Worker exposes the captured-email inbox or deterministic clock controls, or imports the testing injection module; inspect
hosted/server/worker.ts, the build configuration, andhosted/server/tests/worker-entry.ts. -
FAIL IF either installed pgstencil package lacks
dist/provenance.json, recordsdirty, or names a different commit;pnpm-lock.yamlresolves either package from outside npm; or a runtime import depends on a sibling pgstencil checkout. InspectverifyPackagesinhosted/scripts/production.mjs,hosted/server/tests/artifacts.test.ts, and Hosted runtime imports. -
FAIL IF either installed package lacks a verified npm SLSA provenance attestation whose Fulcio certificate SAN names
diffplug/pgstencil.github/workflows/release.ymlonrefs/heads/main, whose source-repository digest (OID1.3.6.1.4.1.57264.1.13) equalsdist/provenance.json's commit, or whose signed subject/payload disagrees with the installed package, certificate, or commit. -
FAIL IF that commit is not on pgstencil
main(gh api repos/diffplug/pgstencil/compare/<commit>...main, statusaheadoridentical), or itssecurity-auditcheck runs (gh api repos/diffplug/pgstencil/commits/<commit>/check-runs) include nosuccess, or any conclusion other thansuccessandcancelled. pgstencil audits the released code; Dormouse audits only how Hosted configures it. -
FAIL IF the local email inbox accepts a foreign Host or Origin or cross-site Fetch Metadata; inspect
allowedDevRequestinhosted/server/dev-host-guard.ts, including the upgrade guard inhosted/server/dev.ts. -
FAIL IF the production deploy can proceed without
preflightestablishing an uncached Hyperdrive, a matching migration/runtime database, and distinct runtime and migration roles; inspectpreflightinhosted/scripts/production.mjsand its ordering ahead of the deploy step in.github/workflows/hosted-production.yml. -
FAIL IF preview mail or OAuth calls reach external providers, preview configuration copies production routes/bindings, or a preview exposes deterministic time controls; inspect
hosted/server/preview-worker.ts,hosted/scripts/preview.mjs, andhosted/server/tests/workers.test.ts.
Pinned by hosted/server/tests/artifacts.test.ts, hosted/server/tests/workers.test.ts, hosted/server/tests/policy.test.ts, hosted/scripts/production.test.mjs.
Production activation, not checked until Hosted is provisioned: the live Hyperdrive and role values that preflight reads, and Cloudflare script injection excluded for the Hosted hostname (hosted/README.md). Checked-in placeholders prove none of them.
Public hosted voice and Relay need their own abuse, authorization, data-disclosure, and recovery checks first; docs/specs/hosted.md owns the staged work.