← back to Dw Domain Fleet

output/vendor-leak-allsites-reverify-2026-06-01.md

74 lines

# Vendor-href leak — ALL-storefronts re-verify (READ-ONLY)
**Run:** 2026-05-31 (overnight, unattended) · **Scope:** 44 dwf-* fleet sites (ports 10001–10044) + 3 standalones · **Mode:** read-only, no edits/deploys

## ⛔ HEADLINE: the fleet is NOT clean — leak is STILL LIVE on all 44 dwf-* sites
The fix commit **a85eb02** ("route PDP buy CTA + main-store anchor + canonical through clean slug") is committed on **Mac2 (HEAD 7fd25ca)** but **was never deployed to Kamatera.** Prod's `dw-domain-fleet` repo is on an unrelated tree **HEAD a6f4037 "initial scaffold"**, whose `shared/render.js` still emits raw vendor handles. This is Mac2↔prod **drift**, not a code defect.

- `render.js` md5 — **Mac2 `7039e2c5…`** (fixed) ≠ **prod `8ec22d71…`** (stale). Confirmed different.
- Prod `product()` still renders (lines ~801/805/705/canonical):
  - `href="${DW}/products/${p.handle}#sample"` ← Order Memo Sample CTA (raw vendor handle)
  - `<a href="${canonical}">View on the main store</a>` where `canonical = ${DW}/products/${p.handle}` (raw)
  - JSON-LD `offers/url: canonical` (raw) + `<link rel=canonical>` (raw)
- Mac2/fixed `product()` routes all of these through `/buy/${productSlug(p)}` (vendor-scrubbed). Correct — just not live.

### 259 confirmed vendor leaks on sampled live vendor PDPs
| Token | Hits | | Kind | Hits |
|-------|------|---|------|------|
| cole-son | 119 | | dw-store-url (JSON-LD/meta/canonical/script) | 148 |
| romo | 70 | | href (anchor tags) | 111 |
| fentucci | 49 | | | |
| clarke-and-clarke | 14 | | | |
| caroline-cecil-textiles | 7 | | | |

Detection = the **production `_VENDOR_SCRUB` regex** loaded from the deployed `render.js` denylist (faithful definition of "a vendor leak"). Raw JSON in `output/leak-reverify-raw.json`; checker in `output/leak-reverify-checker.js`.

### The leak is render-wide — every fleet PDP with a 3rd-party vendor handle leaks
37/44 sites tripped on the single random sample; the other ~6 scored 0 **only because their sampled featured product had a vendor-free handle**, not because they are fixed. Proven empirically — re-sampling the "0-leak" sites' own homepage PDPs:

| Site | Sampled PDP | Raw DW URL in DOM? |
|------|-------------|--------------------|
| cfafabrics (10010) | sausalito-master-plan-fabric-hollywood | YES (vendor-free handle → not flagged) |
| barwallpaper (10006) | fallingwater-charcoal-threads | YES (vendor-free) |
| bleachfriendly (10008) | fallingwater-charcoal-threads | YES (vendor-free) |
| fabricfridays (10016) | sausalito-master-plan-fabric-hollywood | YES (vendor-free) |
| philliperomano (10027) | watch-hill-sand-dune-wallcovering-phillipe-romano | YES (DW private-label, not a 3rd-party leak) |
| restaurantfabrics (10029) | sausalito-master-plan-fabric-hollywood | YES (vendor-free) |

All 44 sites share the identical stale `render.js`; any product whose handle contains a vendor token (cole-son, arte, romo, etc.) leaks on any of them.

`roomsettings (10031)` returned HTTP 429 (rate-limited) on first pass; runs the same stale render.js → same exposure.

## ✅ Standalones (3): href/buy vector CLEAN
All three render `/buy/<vendor-scrubbed-slug>` with **no** raw `designerwallcoverings.com/products/<handle>` URLs and **no** vendor tokens in hrefs/data-handle. The standalone fix (7fd25ca / "deploy Steve-gated") IS effectively live here.

| Standalone | Port | Sampled PDP | Buy link rendered | Raw DW URL | Verdict |
|-----------|------|-------------|-------------------|-----------|---------|
| customdigitalmurals | 9896 | /product/agra-okra-arte-international | `/buy/agra-okra` (scrubbed) | none | CLEAN |
| carmelwallpapers | 9861 | /p/agra-okra-arte-international | `/buy/agra-okra` (scrubbed) | none | CLEAN |
| naturaltextilewallpaper | 9897 | /p/horus-bone-arte | `/buy/horus-bone` (scrubbed) | none | CLEAN |

**Minor non-href note (out of strict scope):** ntw's `<meta name=description>` still contains the vendor NAME as visible text — `"… Horus Bone Wallcovering | Arte International — …"`. Not an href/URL leak, but a vendor-name leak in meta copy. Flagged for awareness; not part of this task's href-leak remediation.
> NB: standalone product cards render client-side (homepage HTML contains JS template literals, not final DOM), so card-link slugs were verified via the server-rendered `/p|/product` PDP, not a headless browser. PDP-internal links are clean; a headless pass would be needed to 100%-confirm the client-rendered grid card hrefs.

## Per-site leak count (fleet)
0 = clean *on the sampled product only* (NOT verified leak-free — see render-wide note above). 7 = leaks found on sampled vendor PDP.
```
10001 1800wallcoverings 7   10012 commercialsalesreps 7   10023 malibuwallpaper 7        10034 stevenabramsphotography 7
10002 asseeninhotels 7      10013 commercialwallcovering 7 10024 montereywallpaper 7       10035 thehotelwallpaper 7
10003 asseeninla 7          10014 designermagnetics 7      10025 naturalwalltextures 7      10036 traditionalwhimsy 7
10004 asseeninmovies 7      10015 etciemurals 7            10026 patterndesignlab 7         10037 unitedstateswallpaper 7
10005 asseeninshowrooms 7   10016 fabricfridays 0*         10027 philliperomano 0*          10038 wallcovering 7
10006 barwallpaper 0*       10017 fireratedwallcovering 7  10028 printmurals 7              10039 wallpaperexports 7
10007 blankstocklining 7    10018 flocked 7                10029 restaurantfabrics 0*       10040 wallpaperfromthe80s 7
10008 bleachfriendly 0*     10019 grassclothwallcovering 7 10030 restaurantmurals 7         10041 wallpaperny 7
10009 carmelwallpaper 7     10020 handmadewallcovering 7   10031 roomsettings 429(unscanned)10042 wallpaperpurchasing 7
10010 cfafabrics 0*         10021 hollywoodwallcovering 7  10032 sheltermagazines 7         10043 wallpaperweekly 7
10011 classawallcovering 7  10022 hospitalitysalesagency 7 10033 specifywallpaper 7         10044 wc01wallcoverings 7
```
`*` = sampled a vendor-free / private-label product; site runs the same stale render.js and WILL leak on vendor-handle products.

## Remediation (GATED — queued for Steve, NOT executed)
DTD verdict **A** (Claude + Codex unanimous, Qwen errored): recommend deploying Mac2 HEAD 7fd25ca to Kamatera, **scoped to `shared/render.js` + targeted pm2 reload** (not a blind full-tree rsync — prod git history diverges, so a one-file sync avoids clobbering prod-authored files). Ready-to-run commands in `~/.claude/yolo-queue/pending-approval/`. Separate non-blocking follow-up: investigate why prod `dw-domain-fleet` git history is an unrelated "initial scaffold".

**Bottom line:** Expected 0 residual leaks; found the fleet still fully leaking because the fix is undeployed. Standalones are clean.