← back to Dw Domain Fleet
output/fleet-vendor-leak-reverify-2026-05-31.md
111 lines
# dw-domain-fleet — vendor-name leak re-verify (rendered DOM)
**Date:** 2026-05-31 · **Mode:** READ-ONLY (no edits, no deploy, no pm2)
**Method:** live-domain `curl` of homepage + up to 5 product pages + /catalog per site; vendor matching mirrors `shared/render.js` `hasVendorToken` exactly (lowercase + strip non-alphanumeric, then substring) — so `modern-carte-blanche` cannot match `arte international` (needle normalizes to `arteinternational`). Self-tested: `carte-blanche`, `the-arte-of-living` → no flag; real vendors → flag.
**Coverage:** 48 sites, 312 pages fetched.
---
## Headline
### ✅ In-scope scrub (slug / handle / data-sku / card-title / tag-chip / aria-label): HOLDING 0 leaks
Across all 48 sites / 312 pages, the May-2026 fleet scrub vectors are **clean** — fleet `/product/<slug>` hrefs, `data-handle`, `data-sku`, `data-title`, visible card titles, `aria-label`, and tag chips carry **no** denylist vendor token. The `modern-carte-blanche` false-positive trap is correctly avoided.
### 🔴 ACTIVE LEAK — outbound DW-store links: **594 leaking links across 43/48 sites** (627 vendor-token matches; a handle like `…-brunschwig-fils` matches two tokens. ≈3 leaking links per affected product page: buy-CTA + canonical + view-store)
On the **product-detail page**, three constructs link DIRECTLY to `designerwallcoverings.com/products/<raw-handle>`, and those handles END in the vendor name. The raw vendor token is therefore present in the rendered DOM:
| render.js | construct | example |
|-----------|-----------|---------|
| `:738` | buy/sample CTA `href="${DW}/products/${p.handle}#sample"` | `…/seasonal-woods-silk-platinum-cole-son#sample` |
| `:632`/`:742` | canonical `<link>` + "View on the main store" anchor (`canonical = ${DW}/products/${p.handle}`) | `…/yasu-silver-brunschwig-fils` |
**Why the scrub didn't catch this:** the scrub cleans the fleet's own *displayed* strings + its own `/product/<slug>`. But the buy/canonical/store links point at the **live DW store handle**, which is never scrubbed. The **quick-view modal does NOT leak** — it routes through the clean `/buy/:slug` 302-redirect (server.js:111). Only the full **product-detail page** links direct.
**Disposition note:** a May-2026 project note (`project_dwf_vendor_slug_scrub_20260529`) flagged the raw buy-CTA handle as *"deferred to source-rename C"* — so this may be a **known/accepted** state rather than a new regression. Surfaced here as an active rendered-DOM exposure regardless. **Per DTD verdict (2026-05-31, A, 2/2): report as a real active leak, do NOT bury under "0".**
**Vector classification:** outbound `href` to DW store (buy-sample CTA / canonical / view-store) — **distinct** from the slug/handle/tag-chip vector that the scrub addresses.
---
## Leaks by vendor token
| token | instances | sample leaking URL |
|-------|-----------|--------------------|
| `romo` | 174 | `https://designerwallcoverings.com/products/seres-stucco-romo` |
| `fentucci` | 168 | `https://designerwallcoverings.com/products/napoli-caramel-basketweave-grasscloth-wallcovering-fentucci` |
| `clarke and clarke` | 75 | `https://designerwallcoverings.com/products/highland-wonder-lagoon-wp-clarke-and-clarke` |
| `cole son` | 66 | `https://designerwallcoverings.com/products/seasonal-woods-silk-platinum-cole-son` |
| `caroline cecil` | 42 | `https://designerwallcoverings.com/products/titik-wp-linen-caroline-cecil-textiles` |
| `brunschwig` | 33 | `https://designerwallcoverings.com/products/yasu-silver-brunschwig-fils` |
| `brunschwig fils` | 33 | `https://designerwallcoverings.com/products/yasu-silver-brunschwig-fils` |
| `andrew martin` | 18 | `https://designerwallcoverings.com/products/nevada-spring-teal-sky-blue-grey-andrew-martin` |
| `gp j baker` | 9 | `https://designerwallcoverings.com/products/tall-trees-delft-blue-g-p-j-baker` |
| `kravet` | 6 | `https://designerwallcoverings.com/products/songbird-sunset-kravet-couture` |
| `versace` | 3 | `https://designerwallcoverings.com/products/versace-4-metallic-wallcovering-as-creation` |
> `romo` (short token) verified genuine — every hit is a `…-romo` handle suffix (the vendor Romo), no substring artifacts (e.g. `philliperomano` does NOT match).
---
## Per-site leak count
### Leaking (outbound-DW-store vector)
| site | leak rows |
|------|-----------|
| 1800wallcoverings.com | 15 |
| asseeninhotels.com | 15 |
| asseeninla.com | 15 |
| asseeninmovies.com | 15 |
| asseeninshowrooms.com | 15 |
| blankstocklining.com | 15 |
| carmelwallpaper.com | 15 |
| classawallcovering.com | 15 |
| commercialsalesreps.com | 15 |
| commercialwallcovering.com | 15 |
| designermagnetics.com | 15 |
| etciemurals.com | 15 |
| fireratedwallcovering.com | 15 |
| flocked.org | 15 |
| grassclothwallcovering.com | 15 |
| handmadewallcovering.com | 15 |
| hospitalitysalesagency.com | 15 |
| malibuwallpaper.com | 15 |
| montereywallpaper.com | 15 |
| naturalwalltextures.com | 15 |
| printmurals.com | 15 |
| restaurantmurals.com | 15 |
| roomsettings.com | 15 |
| sheltermagazines.com | 15 |
| specifywallpaper.com | 15 |
| stevenabramsphotography.com | 15 |
| thehotelwallpaper.com | 15 |
| traditionalwhimsy.com | 15 |
| unitedstateswallpaper.com | 15 |
| wallcovering.net | 15 |
| wallpaperexports.com | 15 |
| wallpaperny.com | 15 |
| wallpaperpurchasing.com | 15 |
| wallpaperweekly.com | 15 |
| wc01wallcoverings.com | 15 |
| bleachfriendly.com | 12 |
| patterndesignlab.com | 12 |
| barwallpaper.com | 9 |
| hollywoodwallcovering.com | 9 |
| wallpaperfromthe80s.com | 9 |
| cfafabrics.com | 6 |
| fabricfridays.com | 6 |
| restaurantfabrics.com | 6 |
### Clean (0 in ALL vectors incl. outbound)
- architecturalwallcoverings.com
- carmelwallpapers.com
- customdigitalmurals.com
- naturaltextilewallpaper.com
- philliperomano.com
> Standalones `customdigitalmurals.com`, `carmelwallpapers.com`, `naturaltextilewallpaper.com`, `architecturalwallcoverings.com` returned 0 leaks but only the **homepage** was auditable — they use `/p/<slug>` routing (not `/product/`) and the homepage exposed no product/buy links to follow. A deeper standalone pass (resolve `/p/` product pages, check their buy CTAs) is recommended before declaring them clean — current result is homepage-only.
---
## Recommended action (Steve-gated — fleet deploy)
Route the product-detail buy/sample CTA + "View on the main store" anchor through the existing clean `/buy/:slug` redirect (as the quick-view modal already does), and emit a vendor-free canonical (or omit canonical). `render.js:632/738/742`. **Not patched here — read-only re-verify; Steve deploys fleet changes.** A queued approval draft accompanies this report.