[object Object]

← back to Dw Domain Fleet

Add 2026-05-31 read-only vendor-leak re-verify: slug/chip scrub holds 0; outbound DW-store href leaks 594 across 43 sites

55a7f0bb1792fc8be75c75ebec4a001db8a1a4de · 2026-05-31 06:39:20 -0700 · Steve Abrams

Files touched

Diff

commit 55a7f0bb1792fc8be75c75ebec4a001db8a1a4de
Author: Steve Abrams <steve@designerwallcoverings.com>
Date:   Sun May 31 06:39:20 2026 -0700

    Add 2026-05-31 read-only vendor-leak re-verify: slug/chip scrub holds 0; outbound DW-store href leaks 594 across 43 sites
---
 output/fleet-vendor-leak-reverify-2026-05-31.md | 110 ++++++++++++++++++++++++
 1 file changed, 110 insertions(+)

diff --git a/output/fleet-vendor-leak-reverify-2026-05-31.md b/output/fleet-vendor-leak-reverify-2026-05-31.md
new file mode 100644
index 0000000..f64a49f
--- /dev/null
+++ b/output/fleet-vendor-leak-reverify-2026-05-31.md
@@ -0,0 +1,110 @@
+# dw-domain-fleet — vendor-name leak re-verify (rendered DOM)
+**Date:** 2026-05-31  ·  **Mode:** READ-ONLY (no edits, no deploy, no pm2)
+**Method:** live-domain `curl` of homepage + up to 5 product pages + /catalog per site; vendor matching mirrors `shared/render.js` `hasVendorToken` exactly (lowercase + strip non-alphanumeric, then substring) — so `modern-carte-blanche` cannot match `arte international` (needle normalizes to `arteinternational`). Self-tested: `carte-blanche`, `the-arte-of-living` → no flag; real vendors → flag.
+**Coverage:** 48 sites, 312 pages fetched.
+
+---
+
+## Headline
+
+### ✅ In-scope scrub (slug / handle / data-sku / card-title / tag-chip / aria-label): HOLDING 0 leaks
+Across all 48 sites / 312 pages, the May-2026 fleet scrub vectors are **clean** — fleet `/product/<slug>` hrefs, `data-handle`, `data-sku`, `data-title`, visible card titles, `aria-label`, and tag chips carry **no** denylist vendor token. The `modern-carte-blanche` false-positive trap is correctly avoided.
+
+### 🔴 ACTIVE LEAK — outbound DW-store links: **594 leaking links across 43/48 sites** (627 vendor-token matches; a handle like `…-brunschwig-fils` matches two tokens. ≈3 leaking links per affected product page: buy-CTA + canonical + view-store)
+On the **product-detail page**, three constructs link DIRECTLY to `designerwallcoverings.com/products/<raw-handle>`, and those handles END in the vendor name. The raw vendor token is therefore present in the rendered DOM:
+
+| render.js | construct | example |
+|-----------|-----------|---------|
+| `:738` | buy/sample CTA `href="${DW}/products/${p.handle}#sample"` | `…/seasonal-woods-silk-platinum-cole-son#sample` |
+| `:632`/`:742` | canonical `<link>` + "View on the main store" anchor (`canonical = ${DW}/products/${p.handle}`) | `…/yasu-silver-brunschwig-fils` |
+
+**Why the scrub didn't catch this:** the scrub cleans the fleet's own *displayed* strings + its own `/product/<slug>`. But the buy/canonical/store links point at the **live DW store handle**, which is never scrubbed. The **quick-view modal does NOT leak** — it routes through the clean `/buy/:slug` 302-redirect (server.js:111). Only the full **product-detail page** links direct.
+
+**Disposition note:** a May-2026 project note (`project_dwf_vendor_slug_scrub_20260529`) flagged the raw buy-CTA handle as *"deferred to source-rename C"* — so this may be a **known/accepted** state rather than a new regression. Surfaced here as an active rendered-DOM exposure regardless. **Per DTD verdict (2026-05-31, A, 2/2): report as a real active leak, do NOT bury under "0".**
+
+**Vector classification:** outbound `href` to DW store (buy-sample CTA / canonical / view-store) — **distinct** from the slug/handle/tag-chip vector that the scrub addresses.
+
+---
+
+## Leaks by vendor token
+
+| token | instances | sample leaking URL |
+|-------|-----------|--------------------|
+| `romo` | 174 | `https://designerwallcoverings.com/products/seres-stucco-romo` |
+| `fentucci` | 168 | `https://designerwallcoverings.com/products/napoli-caramel-basketweave-grasscloth-wallcovering-fentucci` |
+| `clarke and clarke` | 75 | `https://designerwallcoverings.com/products/highland-wonder-lagoon-wp-clarke-and-clarke` |
+| `cole son` | 66 | `https://designerwallcoverings.com/products/seasonal-woods-silk-platinum-cole-son` |
+| `caroline cecil` | 42 | `https://designerwallcoverings.com/products/titik-wp-linen-caroline-cecil-textiles` |
+| `brunschwig` | 33 | `https://designerwallcoverings.com/products/yasu-silver-brunschwig-fils` |
+| `brunschwig fils` | 33 | `https://designerwallcoverings.com/products/yasu-silver-brunschwig-fils` |
+| `andrew martin` | 18 | `https://designerwallcoverings.com/products/nevada-spring-teal-sky-blue-grey-andrew-martin` |
+| `gp j baker` | 9 | `https://designerwallcoverings.com/products/tall-trees-delft-blue-g-p-j-baker` |
+| `kravet` | 6 | `https://designerwallcoverings.com/products/songbird-sunset-kravet-couture` |
+| `versace` | 3 | `https://designerwallcoverings.com/products/versace-4-metallic-wallcovering-as-creation` |
+
+> `romo` (short token) verified genuine — every hit is a `…-romo` handle suffix (the vendor Romo), no substring artifacts (e.g. `philliperomano` does NOT match).
+
+---
+
+## Per-site leak count
+
+### Leaking (outbound-DW-store vector)
+| site | leak rows |
+|------|-----------|
+| 1800wallcoverings.com | 15 |
+| asseeninhotels.com | 15 |
+| asseeninla.com | 15 |
+| asseeninmovies.com | 15 |
+| asseeninshowrooms.com | 15 |
+| blankstocklining.com | 15 |
+| carmelwallpaper.com | 15 |
+| classawallcovering.com | 15 |
+| commercialsalesreps.com | 15 |
+| commercialwallcovering.com | 15 |
+| designermagnetics.com | 15 |
+| etciemurals.com | 15 |
+| fireratedwallcovering.com | 15 |
+| flocked.org | 15 |
+| grassclothwallcovering.com | 15 |
+| handmadewallcovering.com | 15 |
+| hospitalitysalesagency.com | 15 |
+| malibuwallpaper.com | 15 |
+| montereywallpaper.com | 15 |
+| naturalwalltextures.com | 15 |
+| printmurals.com | 15 |
+| restaurantmurals.com | 15 |
+| roomsettings.com | 15 |
+| sheltermagazines.com | 15 |
+| specifywallpaper.com | 15 |
+| stevenabramsphotography.com | 15 |
+| thehotelwallpaper.com | 15 |
+| traditionalwhimsy.com | 15 |
+| unitedstateswallpaper.com | 15 |
+| wallcovering.net | 15 |
+| wallpaperexports.com | 15 |
+| wallpaperny.com | 15 |
+| wallpaperpurchasing.com | 15 |
+| wallpaperweekly.com | 15 |
+| wc01wallcoverings.com | 15 |
+| bleachfriendly.com | 12 |
+| patterndesignlab.com | 12 |
+| barwallpaper.com | 9 |
+| hollywoodwallcovering.com | 9 |
+| wallpaperfromthe80s.com | 9 |
+| cfafabrics.com | 6 |
+| fabricfridays.com | 6 |
+| restaurantfabrics.com | 6 |
+
+### Clean (0 in ALL vectors incl. outbound)
+- architecturalwallcoverings.com
+- carmelwallpapers.com
+- customdigitalmurals.com
+- naturaltextilewallpaper.com
+- philliperomano.com
+
+> Standalones `customdigitalmurals.com`, `carmelwallpapers.com`, `naturaltextilewallpaper.com`, `architecturalwallcoverings.com` returned 0 leaks but only the **homepage** was auditable — they use `/p/<slug>` routing (not `/product/`) and the homepage exposed no product/buy links to follow. A deeper standalone pass (resolve `/p/` product pages, check their buy CTAs) is recommended before declaring them clean — current result is homepage-only.
+
+---
+
+## Recommended action (Steve-gated — fleet deploy)
+Route the product-detail buy/sample CTA + "View on the main store" anchor through the existing clean `/buy/:slug` redirect (as the quick-view modal already does), and emit a vendor-free canonical (or omit canonical). `render.js:632/738/742`. **Not patched here — read-only re-verify; Steve deploys fleet changes.** A queued approval draft accompanies this report.

← 1bdbba0 scrubVendor: optional inter-token separator ([^a-z0-9]*) cat  ·  back to Dw Domain Fleet  ·  Add sort <select> + density control bar to dwf homepage Feat 49997ea →