Skip to content

Commit 104b5c2

Browse files
committed
chore(backlog): start public share hardening
1 parent 739a295 commit 104b5c2

1 file changed

Lines changed: 14 additions & 2 deletions

File tree

‎.backlog/tasks/task-12 - Prevent-public-share-misses-from-polluting-the-catalog-cache.md‎

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,11 @@
11
---
22
id: TASK-12
33
title: Prevent public share misses from polluting the catalog cache
4-
status: To Do
5-
assignee: []
4+
status: In Progress
5+
assignee:
6+
- '@codex'
67
created_date: '2026-07-15 15:58'
8+
updated_date: '2026-07-15 18:11'
79
labels:
810
- security
911
- availability
@@ -36,3 +38,13 @@ Cached.get_deck_by_share_token stores lookup misses under the raw public token i
3638
- [ ] #5 Public routes preserve their current response contracts for not found, existing shares, content types, and GraphQL null/error behavior.
3739
- [ ] #6 Focused tests inspect producer/database call counts and cache contents for malformed, valid-missing, valid-existing, rotated, and deleted tokens across every public entry point.
3840
<!-- AC:END -->
41+
42+
## Implementation Plan
43+
44+
<!-- SECTION:PLAN:BEGIN -->
45+
1. Define and enforce the generated share-token contract at every public HTML, SVG/PNG preview, and public GraphQL boundary before any cache lookup.
46+
2. Ensure malformed and valid-missing requests never enter the shared positive deck cache while valid existing tokens retain positive caching and invalidation.
47+
3. Preserve not-found, content-type, GraphQL null/error, rotation/removal, and deletion response contracts.
48+
4. Add focused producer/database call-count and cache-content coverage across malformed, missing, existing, rotated, removed, and deleted tokens.
49+
5. Verify focused public-share/cache suites, full backend tests, warnings-fatal compilation, and strict Credo.
50+
<!-- SECTION:PLAN:END -->

0 commit comments

Comments
 (0)