Secrets Manager

repo: ~/Projects/secrets-manager · 214 commits · 2 in last 24h, 17 in last 7d · █▆▃▂▃

Search the build

214 commits indexed

  1. eb703f4 2026-09-26 rotate-dw-admin-full.sh: client-side SCRAM-SHA-256 so plaintext never reaches Postgres (TK-11480)
  2. 5673bb9 2026-09-26 rotate-dw-admin-full.sh: repair 4 reproduced defects + synthetic harness (TK-11480)
  3. 576e596 2026-09-25 auto-data-snapshot: 2026-09-25T11:52:49 (1 data files) — registry.json
  4. 4464cbf 2026-09-24 auto-data-snapshot: 2026-09-24T14:21:31 (1 data files) — registry.json
  5. 4efb136 2026-09-23 routes: register Kamatera full-monte/.env as a GEMINI_API_KEY destination (enrichment key switched off depleted account, TK-12090)
  6. b5cdf49 2026-09-23 auto-data-snapshot: 2026-09-23T12:42:16 (1 data files) — registry.json
  7. c7c44d9 2026-09-23 TK-12029: DW_SESSION_SECRET route moved to services.* with env_file destinations (bare top-level array was silently ignored by fanOut)
  8. 474abf9 2026-09-23 TK-12029: route DW_SESSION_SECRET to all three local HMAC verifiers (room-setting-app, ImportNewSkufromURL, Letsbegin)
  9. 1ebb068 2026-09-23 register GEMINI_API_KEY_PATTY + GEMINI_API_KEY_POPPY — fixes unrouted leak targets for TK-11786 Gemini rotation
  10. 0a9d893 2026-09-23 auto-data-snapshot: 2026-09-23T09:31:43 (1 data files) — registry.json
  11. 64fcb40 2026-09-22 auto-data-snapshot: 2026-09-22T16:42:26 (1 data files) — registry.json
  12. 5b2b417 2026-09-22 auto-data-snapshot: 2026-09-22T16:09:18 (1 data files) — registry.json
  13. 542d9ff 2026-09-22 routes: register BROWSERBASE_API_KEY + PROJECT_ID destinations (were unrouted → stale key shadowed ImportNewSkufromURL, causing fleet-wide BB 401)
  14. 3c08671 2026-09-22 verify: okStatuses now requires a paired bodyMustContain body proof to certify a key
  15. ceab226 2026-09-22 Register DW_SESSION_SECRET route -> room-setting-app/.env.local (TK-11786 auth fix wiring)
  16. 30819c4 2026-09-22 auto-data-snapshot: 2026-09-22T12:49:04 (2 data files) — registry.json routes.json
  17. 08b3e97 2026-09-22 auto-data-snapshot: 2026-09-22T12:15:47 (3 data files) — data/latest.json registry.json routes.json
  18. 5ed32a4 2026-09-18 auto-data-snapshot: 2026-09-18T14:54:24 (1 data files) — registry.json
  19. 368acb8 2026-09-17 auto-data-snapshot: 2026-09-17T11:32:24 (1 data files) — registry.json
  20. af8153b 2026-09-17 auto-data-snapshot: 2026-09-17T09:53:49 (2 data files) — registry.json routes.json
  21. b0935a9 2026-09-16 TK-11683: document ENOENT-exclusion tradeoff (codex-check/Grok) — single-cycle self-healing vs chronic-WARN masking
  22. 11e21a4 2026-09-16 TK-11683: harden transcript scanner read loop (mid-write race) — retry-read once + exclude ENOENT-vanished files from unreadable, add fail-safe negative test
  23. 7c0d555 2026-09-16 auto-data-snapshot: 2026-09-16T10:07:35 (1 data files) — registry.json
  24. 0a2ee5b 2026-09-14 TK-11745: stage collision-safe Stripe live-key routes for professional-directory rotation fan-out
  25. 9bbbe67 2026-09-14 TK-11683: reversible dry-run redactor for Claude session transcripts
  26. 0795811 2026-09-14 TK-11683: read-only live-secret scanner for Claude session transcripts
  27. 4930415 2026-09-13 auto-data-snapshot: 2026-09-13T03:09:46 (1 data files) — routes.json
  28. cd4cd10 2026-09-13 secrets routes: add govarbitrage as GOOGLE_PLACES_API_KEY fan-out destination
  29. cc062c2 2026-09-12 TK-11502: register SHOPIFY_ADMIN_ACCESS_TOKEN as managed key (verify=Shopify Admin shop.json), stop TK-10930 drift
  30. bf737ca 2026-09-11 auto-data-snapshot: 2026-09-11T12:47:38 (1 data files) — registry.json
  31. 98ffa8e 2026-09-11 auto-data-snapshot: 2026-09-11T08:57:34 (1 data files) — routes.json
  32. 287df5a 2026-09-08 routes: add DEEPSEEK_API_KEY with DeepSeek balance verify endpoint
  33. 346ba84 2026-09-08 auto-data-snapshot: 2026-09-08T09:40:47 (1 data files) — registry.json
  34. 2532072 2026-09-08 auto-data-snapshot: 2026-09-08T09:02:39 (1 data files) — registry.json
  35. 1f37027 2026-09-04 auto-data-snapshot: 2026-09-04T09:09:45 (2 data files) — registry.json routes.json
  36. 90f733b 2026-09-03 auto-data-snapshot: 2026-09-03T14:29:24 (1 data files) — routes.json
  37. 9e77f88 2026-09-03 auto-data-snapshot: 2026-09-03T07:56:56 (1 data files) — registry.json
  38. 9036967 2026-09-03 Route Charge and Explore test webhook secret
  39. 3990c33 2026-09-03 Route Charge and Explore Stripe test key
  40. d972b48 2026-09-02 add safe local credentials center
  41. 08ddb77 2026-09-02 auto-data-snapshot: 2026-09-02T17:24:05 (1 data files) — verification/credentials-center-e2e.png
  42. 17a01c9 2026-09-01 auto-data-snapshot: 2026-09-01T07:51:05 (1 data files) — registry.json
  43. 1e0b985 2026-08-31 auto-data-snapshot: 2026-08-31T17:38:21 (1 data files) — registry.json
  44. 891f556 2026-08-31 auto-data-snapshot: 2026-08-31T11:17:15 (1 data files) — tk11025-restore-map.json
  45. 4df7ff6 2026-08-31 rotate xAI and Moonshot credential records
  46. 8cc46a5 2026-08-31 Push Grok key to remote DTD panel
  47. 1881ae9 2026-08-31 Route Grok key to remote DTD panel
  48. 4bc2dfa 2026-08-31 auto-data-snapshot: 2026-08-31T02:00:54 (2 data files) — remote-routes.json routes.json
  49. 015d8a6 2026-08-31 auto-data-snapshot: 2026-08-31T00:07:16 (1 data files) — registry.json
  50. d56076d 2026-08-30 auto-data-snapshot: 2026-08-30T21:32:01 (1 data files) — registry.json
  51. 063ec71 2026-08-30 auto-data-snapshot: 2026-08-30T19:40:35 (1 data files) — registry.json
  52. 82baf8b 2026-08-29 register Norma reels authorization route
  53. cae0e8c 2026-08-29 quote spaced secrets for shell consumers
  54. 87ca939 2026-08-29 auto-data-snapshot: 2026-08-29T12:47:37 (2 data files) — registry.json routes.json
  55. 2363f17 2026-08-28 Sanitize verifier report fields
  56. f585023 2026-08-28 Harden secret freshness verification failures
  57. 76a6bf3 2026-08-28 Add secret freshness report command
  58. b712be4 2026-08-28 register Shopify full-access token routes
  59. 6205d31 2026-08-28 auto-data-snapshot: 2026-08-28T07:45:44 (2 data files) — registry.json routes.json
  60. 11003cd 2026-08-28 auto-data-snapshot: 2026-08-28T06:30:22 (1 data files) — registry.json
  61. 0b03b92 2026-08-28 auto-data-snapshot: 2026-08-28T01:33:48 (1 data files) — routes.json
  62. c9561cd 2026-08-28 auto-data-snapshot: 2026-08-28T00:56:56 (2 data files) — registry.json routes.json
  63. 82ca00d 2026-08-26 auto-data-snapshot: 2026-08-26T08:21:31 (1 data files) — registry.json
  64. 77e01b5 2026-08-19 auto-data-snapshot: 2026-08-19T11:14:55 (1 data files) — registry.json
  65. ea8709c 2026-08-19 auto-data-snapshot: 2026-08-19T09:34:55 (1 data files) — registry.json
  66. 141197b 2026-08-14 auto-data-snapshot: 2026-08-14T13:55:45 (1 data files) — registry.json
  67. 35d45b7 2026-08-12 auto-data-snapshot: 2026-08-12T17:03:39 (1 data files) — registry.json
  68. cc73261 2026-08-12 auto-data-snapshot: 2026-08-12T09:56:27 (1 data files) — registry.json
  69. 34dcb5d 2026-08-11 secrets: backup-before-overwrite guard in writeEnvFile (timestamped .bak on real change, prune last 5) — born from the ZENDESK secret incident
  70. 1465ee8 2026-08-11 auto-data-snapshot: 2026-08-11T07:04:50 (1 data files) — registry.json
  71. bb1e570 2026-08-10 auto-data-snapshot: 2026-08-10T22:20:03 (1 data files) — registry.json
  72. 671c2d3 2026-08-10 auto-data-snapshot: 2026-08-10T21:49:05 (1 data files) — registry.json
  73. 9e29295 2026-08-10 auto-data-snapshot: 2026-08-10T15:38:06 (1 data files) — registry.json
  74. 05ae97c 2026-08-10 auto-data-snapshot: 2026-08-10T14:35:45 (1 data files) — registry.json
  75. a134765 2026-08-10 auto-data-snapshot: 2026-08-10T13:34:07 (1 data files) — registry.json
  76. 0b2ec88 2026-08-10 auto-data-snapshot: 2026-08-10T10:58:17 (2 data files) — registry.json routes.json
  77. f5bf9c3 2026-08-10 auto-data-snapshot: 2026-08-10T10:27:30 (1 data files) — registry.json
  78. 7de1947 2026-08-10 auto-data-snapshot: 2026-08-10T09:25:36 (1 data files) — registry.json
  79. 0d61dd5 2026-08-09 auto-data-snapshot: 2026-08-09T09:46:33 (3 data files) — registry.json routes.json routes.json.bak.1786292832
  80. 3ec1257 2026-08-07 auto-data-snapshot: 2026-08-07T10:09:04 (1 data files) — registry.json
  81. 94d6549 2026-08-06 auto-data-snapshot: 2026-08-06T15:32:11 (1 data files) — registry.json
  82. f2c9818 2026-08-06 auto-data-snapshot: 2026-08-06T14:29:57 (1 data files) — registry.json
  83. 769e028 2026-08-05 routes: fan BRAVE_SEARCH_API_KEY to rentv/.env (PR LinkedIn enrichment)
  84. 6c6f7be 2026-08-05 auto-save: 2026-08-05T14:12:38 (1 files) — registry.json
  85. d1886dc 2026-08-05 auto-save: 2026-08-05T12:11:52 (1 files) — registry.json
  86. cc9dcfe 2026-08-05 auto-save: 2026-08-05T08:40:35 (1 files) — registry.json
  87. fa122d3 2026-08-04 auto-save: 2026-08-04T13:03:31 (1 files) — registry.json
  88. 98cf4a1 2026-08-04 auto-save: 2026-08-04T11:32:54 (1 files) — registry.json
  89. 61fc594 2026-08-04 auto-save: 2026-08-04T10:32:27 (1 files) — registry.json
  90. a198f88 2026-08-03 auto-save: 2026-08-03T12:23:59 (1 files) — registry.json
  91. c68e00d 2026-08-03 auto-save: 2026-08-03T11:53:46 (1 files) — registry.json
  92. 31eccc0 2026-08-03 auto-save: 2026-08-03T10:23:02 (2 files) — registry.json routes.json
  93. c560ed9 2026-08-02 auto-save: 2026-08-02T07:13:15 (1 files) — registry.json
  94. 28bb624 2026-07-30 secrets: DSN_REWRITE superset fix — map real dw_admin PG key names to DATABASE_URL so DB rotation rewrites the DSN (TK-10045, fixes half-fire)
  95. d7a8605 2026-07-30 auto-save: 2026-07-30T15:19:04 (1 files) — registry.json
  96. 86c3ed3 2026-07-30 secrets: record rotated OPENAI_API_KEY digest in registry (session close)
  97. 60e3fb0 2026-07-30 secrets: extend OPENAI_API_KEY route to holdforme/model-arena/wallco-ai/whatsmystyle/B_Version_1 (were on dead key)
  98. 642707c 2026-07-30 auto-save: 2026-07-30T08:16:08 (1 files) — registry.json
  99. acccd86 2026-07-30 auto-save: 2026-07-30T07:45:45 (1 files) — registry.json
  100. a6259c8 2026-07-30 secrets-manager: fix 2 pre-existing fan bugs (contrarian Hole 4, TK-10045)
  101. f9531b0 2026-07-29 scoping: mark skill .env as review_required (Claude-consumed, not grep-visible) + apply scoped .env to 13 code-scanned non-live projects (TK-10045)
  102. dda3d54 2026-07-29 auto-save: 2026-07-29T22:42:47 (2 files) — registry.json ROTATION-TEMPLATE.env
  103. a124191 2026-07-29 secrets-manager scoping: fix 3 contrarian-found defects (TK-10045)
  104. 7795cb8 2026-07-29 secrets-manager: least-privilege scoping (TK-10045) — derive-manifests.js + regen command + manifest-aware fanOut guard (SCOPED_FANOUT-gated)
  105. 9c94c8a 2026-07-27 auto-save: 2026-07-27T09:19:22 (2 files) — registry.json routes.json
  106. 9309659 2026-07-26 auto-save: 2026-07-26T16:14:26 (1 files) — registry.json
  107. 5907daf 2026-07-23 routes: GEMINI_API_KEY_WALLCO -> model-arena (image tool fallback backend)
  108. 6c945b4 2026-07-23 routes: ADOBE_CLIENT_ID/SECRET + FIGMA_TOKEN -> model-arena .env (design tools)
  109. 6c6d1f8 2026-07-22 auto-save: 2026-07-22T17:45:47 (1 files) — registry.json
  110. 4604d18 2026-07-22 auto-save: 2026-07-22T14:44:58 (2 files) — registry.json routes.json
  111. 367cf90 2026-07-22 auto-save: 2026-07-22T13:14:23 (4 files) — dw-scroll-debug.js dw-scroll-debug2.js dw-scroll-debug3.js dw-scroll-verify.js
  112. 2b76a66 2026-07-22 chore: refactor — rename GOOGLE→GOOGLE_YOUTUBE for clarity (session close, no behavior change)
  113. d27dd68 2026-07-22 auto-save: 2026-07-22T10:13:11 (2 files) — registry.json routes.json
  114. aaa98bd 2026-07-22 Coordonné Cotswolds: activate 29 wallcoverings LIVE (ACTIVE + Online Store + New Arrival, Google excluded 0/29) per DTD verdict B; 8 murals held with Coco Dávez batch
  115. ffff533 2026-07-22 Coordonné Cotswolds (Ybarra & Serret): create 37 settlement-OK SKUs as DRAFT on Shopify (0 channels), PG-first→Shopify, $4.25 sample + real $169/$113.62 sellable variant; 10 BLOCK held
  116. e908b8f 2026-07-22 Coordonné Cotswolds (Coco Dávez): settlement post-gen-vision gate — 47 rows, 37 OK / 10 BLOCK (5 Royal-Oak + 5 Mallard-Duck, all Part-B bird catches; gemini-2.5-flash)
  117. 2930b39 2026-07-22 Coordonné Coco Dávez: create 16 held murals @ $113.62 (DTD Option C); collection now 54/54 by real membership
  118. b45ce41 2026-07-22 auto-save: 2026-07-22T09:12:53 (5 files) — coordonne-collab-audit/coco-create-result.json _shopify_channel_fill.py coordonne-collab-audit/check-membership.js coordonne-collab-audit/coco-create-mural.json coordonne-collab-audit/create-coco-mural.js
  119. 4614978 2026-07-22 Coco Dávez canary: create 38 $169 wallcoverings PG-first→Shopify, publish to Online Store; 16 murals HELD per DTD-C (pricing differs $113.62)
  120. bdb8510 2026-07-22 Coco Dávez: settlement post-gen-vision gate — 54/54 OK, 0 BLOCK (gemini-2.5-flash)
  121. 9908896 2026-07-22 Coordonné: tag 11 Artisan overmatch fabrics with Artisan By Bodo Sperlein (ADD-only)
  122. 9332543 2026-07-22 Coordonné Phase 1: ADD-only tag 52 Artisan + 48 CSM live DWDC products; both smart-collections populated (52/48)
  123. d09d321 2026-07-22 auto-save: 2026-07-22T07:42:20 (1 files) — audits/
  124. 3d0b1df 2026-07-21 auto-save: 2026-07-21T18:09:04 (3 files) — hero-image-fallback.py hero-polish.py set-categories.py
  125. e415f0e 2026-07-21 auto-save: 2026-07-21T17:38:50 (1 files) — deploy-faqs-bymaterial.py
  126. 1b7fdd1 2026-07-21 auto-save: 2026-07-21T17:08:42 (5 files) — deploy-collection-faqs.py greenland-cleanup-backups/dw-collection-hero-BACKUP-banner.liquid greenland-cleanup-backups/dw-collection-hero-BACKUP-v2pre.liquid halve-banner.py update-collection-aeo-v2.py
  127. fc3b6fb 2026-07-21 auto-save: 2026-07-21T16:38:33 (3 files) — deploy-collection-aeo.py find-theme-token.sh greenland-cleanup-backups/dw-collection-hero-BACKUP-20260721-manual.liquid
  128. 1afa936 2026-07-21 auto-save: 2026-07-21T16:08:25 (1 files) — greenland-cleanup-backups/live-titles-backup-20260721-154549.tsv
  129. e6f3f31 2026-07-21 Greenland leak cleanup: archive-duplicates script + mirror-orphan backup/plan
  130. 48f095f 2026-07-21 auto-save: 2026-07-21T14:38:01 (3 files) — add-blog-images.py fix-pr-naturals-schema.py publish-pr-naturals-blog.py
  131. 95b77ef 2026-07-21 auto-save: 2026-07-21T14:07:54 (3 files) — alias-content-token.py find-content-token.sh publish-creatures-article.py
  132. be72efe 2026-07-20 auto-save: 2026-07-20T13:32:24 (1 files) — registry.json
  133. 4bc9b1f 2026-07-20 auto-save: 2026-07-20T12:32:08 (2 files) — registry.json routes.json
  134. 2c94ffa 2026-07-20 auto-save: 2026-07-20T10:01:15 (2 files) — registry.json routes.json
  135. 2f5c548 2026-07-17 auto-save: 2026-07-17T11:46:26 (1 files) — registry.json
  136. 30d247e 2026-07-17 Add Threads (Meta) key routes → MCC .env
  137. 7183244 2026-07-17 auto-save: 2026-07-17T10:46:15 (2 files) — registry.json routes.json
  138. 30d2c8d 2026-07-16 auto-save: 2026-07-16T08:42:12 (1 files) — registry.json
  139. 77e1515 2026-07-15 auto-save: 2026-07-15T14:07:06 (1 files) — registry.json
  140. 6fddcb6 2026-07-15 auto-save: 2026-07-15T09:35:38 (1 files) — registry.json
  141. 53e2a80 2026-07-14 routes: pre-stage TikTok client key/secret fan-out to marketing-command-center (local + Kamatera live .env)
  142. 1e02273 2026-07-14 auto-save: 2026-07-14T10:00:24 (1 files) — registry.json
  143. e0ef307 2026-07-14 auto-save: 2026-07-14T09:00:07 (1 files) — registry.json
  144. aa8138c 2026-07-14 auto-save: 2026-07-14T07:59:52 (1 files) — registry.json
  145. 3718887 2026-07-13 auto-save: 2026-07-13T15:55:55 (2 files) — registry.json routes.json
  146. 54f0bcc 2026-07-13 routes: fan Meta/IG token to Norma instagram-agent .env (sync master+MCC+Norma+canary on one paste)
  147. 83d15ae 2026-07-12 auto-save: 2026-07-12T10:17:36 (2 files) — registry.json routes.json
  148. becc8fb 2026-07-10 auto-save: 2026-07-10T11:07:57 (1 files) — registry.json
  149. 19c6f0c 2026-07-10 auto-save: 2026-07-10T00:12:54 (1 files) — registry.json
  150. e8a1031 2026-07-10 routes: add YORKWALL_USER/PASS fan-out for brewster/york scraper
  151. 6a60280 2026-07-09 auto-save: 2026-07-09T23:42:48 (2 files) — registry.json routes.json
  152. b8a2534 2026-07-09 secrets: arm Low+Medium remote routes per Steve go + DTD-A (31 keys; GEORGE_AUTH kept manual)
  153. fa26afa 2026-07-09 secrets: fleet secrets→service audit → remote-routes.proposed.json (32 candidates, review-before-arm; live routes unchanged)
  154. 15d072c 2026-07-09 secrets: register Browserbase key+project-id as remote routes → all-dw prod .env (rotation push-remote coverage)
  155. 2c78874 2026-07-09 secrets: explicit remote-route push (push-remote.js) for CF token → Kamatera all-dw .env + pm2 reload; compare-first no-op; sync stays local-only (remote push is opt-in)
  156. a8646ea 2026-07-09 auto-save: 2026-07-09T18:11:36 (3 files) — cli.js remote-routes.json scripts/push-remote.js
  157. 9c999a3 2026-07-09 auto-save: 2026-07-09T17:11:25 (1 files) — routes.json
  158. 08c4c57 2026-07-08 auto-save: 2026-07-08T15:06:23 (1 files) — registry.json
  159. ab4778a 2026-07-08 auto-save: 2026-07-08T10:05:08 (1 files) — registry.json
  160. 77326d9 2026-07-08 auto-save: 2026-07-08T09:35:02 (1 files) — registry.json
  161. ff4755c 2026-07-07 auto-save: 2026-07-07T10:30:01 (1 files) — registry.json
  162. 7e4f32e 2026-07-07 auto-save: 2026-07-07T09:59:53 (1 files) — registry.json
  163. 75dc44c 2026-07-07 browserbase: pre-stage one-shot prod dedicated-key swap helper (+gitignore stage secrets)
  164. a9ae69e 2026-07-07 auto-save: 2026-07-07T08:56:34 (2 files) — registry.json stage/
  165. 627cc26 2026-07-07 browserbase: unhook Kamatera prod all-dw from shared key fan-out (dedicated prod key set out-of-band)
  166. 53a3c70 2026-07-07 routes: fan Browserbase creds to all-designerwallcoverings (local + Kamatera .env) for the live-scrape backend
  167. b2ee568 2026-07-03 chore: macstudio3 migration — reconcile from mac2 + repoint paths (stevestudio2→macstudio3, node/npm/npx→/opt/homebrew)
  168. 43cd764 2026-06-30 auto-save: 2026-06-30T16:41:53 (1 files) — registry.json
  169. fd2a12b 2026-06-30 routes: add SHOPIFY store domain / sample variant / storefront token for vendor microsites
  170. 430f55c 2026-06-29 auto-save: 2026-06-29T15:54:24 (1 files) — registry.json
  171. 6f50c9b 2026-06-29 auto-save: 2026-06-29T10:48:32 (2 files) — registry.json routes.json
  172. 307a2a6 2026-06-27 auto-save: 2026-06-27T01:06:38 (2 files) — registry.json routes.json
  173. 1679ff2 2026-06-26 auto-save: 2026-06-26T15:04:14 (2 files) — registry.json routes.json
  174. bac2bac 2026-06-26 auto-save: 2026-06-26T11:45:25 (1 files) — registry.json
  175. e6940f5 2026-06-25 Route SHOPIFY_THEME_TOKEN to DW-Agents env files (token scrubbed from source)
  176. 5355d14 2026-06-24 Pre-wire GOOGLE_OAUTH_CLIENT_ID/SECRET routes to dw-activation-calendar/.env
  177. e93bf2c 2026-06-24 auto-save: 2026-06-24T13:27:11 (1 files) — registry.json
  178. bc755b5 2026-06-24 auto-save: 2026-06-24T12:57:01 (1 files) — registry.json
  179. ac2d3d8 2026-06-23 secrets: pre-stage GEMINI_API_KEY_DW_ENRICH route (empty) for leaked-key rotation — instant fan on Steve's new key
  180. 201ce58 2026-06-23 auto-save: 2026-06-23T12:21:34 (1 files) — registry.json
  181. a8db056 2026-06-23 auto-save: 2026-06-23T09:20:41 (1 files) — registry.json
  182. 8aeb1ce 2026-06-23 auto-save: 2026-06-23T08:50:33 (1 files) — registry.json
  183. 55f7d51 2026-06-22 auto-save: 2026-06-22T21:17:54 (1 files) — registry.json
  184. b269ff0 2026-06-22 auto-save: 2026-06-22T10:35:23 (1 files) — registry.json
  185. bc23c75 2026-06-21 auto-save: 2026-06-21T20:01:45 (2 files) — registry.json routes.json
  186. af4923b 2026-06-21 auto-save: 2026-06-21T19:01:26 (1 files) — CF-TOKEN-LEAK-ROTATION-BLOCKED-20260621.md
  187. 74dfa62 2026-06-21 auto-save: 2026-06-21T18:53:00 (7 files) — .gitignore registry.json registry.json.bak.20260507-122845 routes.json.bak-1779124119 routes.json.bak.20260505-fanout
  188. 7fe7f4e 2026-06-21 Reconcile ROTATION-CHECKLIST against 2026-06-21 read-only verification: dw_admin item #1 still genuinely OUTSTANDING (old pw live in 4 DSNs, canonical fan key unset); Shopify item #4 was STALE -> RESOLVED (token HTTP 200). DTD verdict A unanimous: compromised flag stays.
  189. 2297149 2026-06-19 secrets: add PG_DW_ADMIN_PASSWORD fan route (4 env_file dests) — unblocks dw_admin rotation fan
  190. 333c740 2026-06-18 Route SHOPIFY_DRAFT_TOKEN (full-access, write_draft_orders) → DW mural PDP checkout
  191. da036c7 2026-06-16 Add automated encrypted off-box backup of secrets master (.env)
  192. f342dbe 2026-06-15 feat: backup-env.sh — encrypted off-box backup of canonical .env (ciphertext-only to gdrive); dry-run default, --apply gated
  193. e1b76f7 2026-06-11 retire Desktop secret mirror (~/Desktop/site-factory.env) — DTD verdict A
  194. 93d8391 2026-06-09 fan-out: honor per-destination d.key remap in env_file branch (was writing master key name, ignoring remap); route SHOPIFY_ADMIN_TOKEN -> ImportNewSkufromURL/.env.local as SHOPIFY_ADMIN_ACCESS_TOKEN
  195. 41aafea 2026-06-09 fix secrets fan: top-level routes invisible (22) + dw_admin never rewrote DATABASE_URL
  196. 8b0e8f0 2026-06-03 add rotate-dw-admin-full.sh — complete the forward dw_admin rotation
  197. 4e224ba 2026-06-03 secrets viewer: add read-only /rotation page (renders ROTATION-CHECKLIST.md as status cards)
  198. f461d5c 2026-06-01 update tracker: add 'to configure' section for 16 not-set keys (mint links + route-back templates)
  199. c35aa92 2026-06-01 credentials/tokens update tracker web viewer (:9778) + dw_admin rotation pre-stage doc
  200. 4fbb01c 2026-06-01 Add credential rotation checklist (dw_admin pw + 2 Gemini keys + DTD-cleared Norma scoped rotation)
  201. 89bebba 2026-05-31 durable daily post-bubbe Tier-1 secret-rotation reminder
  202. a1e5d79 2026-05-31 gitignore: add patterns for backup/scratch files (*.bak, *.bak-*, *.pre-*, *.orig etc)
  203. ed8feec 2026-05-19 chore: sync registry + routes
  204. ebc0fdc 2026-05-19 snapshot — gitify backup 2026-05-19
  205. 17d9512 2026-05-13 fix env wiring — add 22 DW microsites to admin-passes + GEORGE_AUTH routes
  206. d6a1fe6 2026-05-13 snapshot: backup uncommitted work (1 files)
  207. 4adfd0a 2026-05-13 snapshot: 3 file(s) changed, +1 new, ~2 modified
  208. 6033408 2026-05-12 feat(secrets): TMDB_API_KEY + TMDB_READ_ACCESS_TOKEN routes (asseeninmovies/.env)
  209. 5afad01 2026-05-07 log: 9-domain batch DNS+cert session 2026-05-07
  210. 6d8118e 2026-05-07 tighten .gitignore: add missing standing-rule patterns (tmp/)
  211. 56e6b61 2026-05-07 remove ANTHROPIC_API_KEY from registry per standing rule (Max-plan only)
  212. f2bf483 2026-05-06 fix: envEscape() so #-containing values keep quotes through sync
  213. e14bede 2026-05-06 routes: add NPH (Mac2 + Kamatera) to STRIPE_SECRET_KEY + STRIPE_PUBLISHABLE_KEY fan-out
  214. 05d62f1 2026-05-04 [overnight] pre-debate baseline

Authors

Agents used

  • secrets-manager6

Skills used

  • /claude11
  • /code11
  • /dw-collection-hero-3
  • /latest2
  • /rotation2
  • /rotate-dw-admin-full1
  • /projects1
  • /private-key1
  • /sendgrid1
  • /twilio1
  • /bearer1
  • /env-key1
  • /placeholder1
  • /credentials-center-e2e1
  • /model-arena1
  • /wallco-ai1
  • /whatsmystyle1
  • /undefined1
  • /shell1
  • /coco-create-result1
  • /check-membership1
  • /coco-create-mural1
  • /create-coco-mural1
  • /live-titles-backup-20260721-1545491
  • /plan1
  • /secret1
  • /york1
  • /push-remote1
  • /npm1
  • /npx1

Creative ideas + design notes

Commits with substantial prose (≥120 chars) — the rationale behind each move.

eb703f4 · 2026-09-26 · rotate-dw-admin-full.sh: client-side SCRAM-SHA-256 so plaintext never reaches Postgres (TK-11480)
ALTER now carries a pre-hashed verifier (pw to python on stdin, never argv), so
log_statement / pg_stat_statements can never capture the plaintext. Harness T6
proves it on a real throwaway PG14 cluster (TCP-only; new pw authenticates, wrong
pw rejected) and goes RED on a corrupted verifier. T6 fails NOT-MEASURED if the
cluster does not start (fixed a false-green negative control). 22/22 green.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01J3gBZfBgR2c7TZugF5Ybz4
5673bb9 · 2026-09-26 · rotate-dw-admin-full.sh: repair 4 reproduced defects + synthetic harness (TK-11480)
Fixes: password in python3 argv (now printf builtin); ssh pipe+heredoc stdin
collision (script now the ssh command, pw alone on stdin); CHG passed as argv
not env (zero restarts); no errexit (failed Mac2 ALTER continued to prod).
Hardening per contrarian review: pm2 jlist failure fails closed (was a silent
zero-restart via process substitution), exclusive timestamped backups, opt-in
split-brain start, broad-cwd restart guard, partial-rotation STATE report,
xtrace disabled. test/rotate-dw-admin-full.test.sh: 19/19 green; RED vs original.
No secret read, script never executed against a real host.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01J3gBZfBgR2c7TZugF5Ybz4
c7c44d9 · 2026-09-23 · TK-12029: DW_SESSION_SECRET route moved to services.* with env_file destinations (bare top-level array was silently ignored by fanOut)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136w4V3yGy3mAqRf1dtgYkr
474abf9 · 2026-09-23 · TK-12029: route DW_SESSION_SECRET to all three local HMAC verifiers (room-setting-app, ImportNewSkufromURL, Letsbegin)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136w4V3yGy3mAqRf1dtgYkr
3c08671 · 2026-09-22 · verify: okStatuses now requires a paired bodyMustContain body proof to certify a key
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DP24DdLpG6PHXgmjr47TVb
ceab226 · 2026-09-22 · Register DW_SESSION_SECRET route -> room-setting-app/.env.local (TK-11786 auth fix wiring)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G3ChReG53fwpNgUESv4SY7
b0935a9 · 2026-09-16 · TK-11683: document ENOENT-exclusion tradeoff (codex-check/Grok) — single-cycle self-healing vs chronic-WARN masking
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qf3DHSrZSGBXkNENgsYdM8
11e21a4 · 2026-09-16 · TK-11683: harden transcript scanner read loop (mid-write race) — retry-read once + exclude ENOENT-vanished files from unreadable, add fail-safe negative test
A live transcript caught mid-write or rotated away between find-enumeration and
read (TK-11795) flipped the whole canary to WARN 'cannot certify clean'. Now:
retry the read once after a 150ms sync sleep for the transient case; a VANISHED
file (ENOENT — no longer on disk, so it cannot hold a persistent secret) is
excluded rather than counted as an unmeasured gap; a genuinely-unreadable
(non-ENOENT) file surviving the retry still counts unreadable -> WARN. Negative
test extended to prove the fail-safe direction holds (EACCES file -> WARN).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qf3DHSrZSGBXkNENgsYdM8
9bbbe67 · 2026-09-14 · TK-11683: reversible dry-run redactor for Claude session transcripts
Masks high-confidence live-secret spans (the hc:true patterns the scanner
flags, shared via transcript-secret-lib.mjs so redaction touches exactly what
the scan reports) with a REDACTED:pattern:last4:sha16 placeholder.

Reversibility: backs up each file (chmod 600) BEFORE any write, records a
restore-map (sha_before/sha_after + redacted digests, never a raw value), and
--restore reverses byte-for-byte. Dry-run is the DEFAULT; a live --apply is
refused without an explicit --yes-modify-live confirm flag. Ships a negative
test proving dry-run is a no-op, --apply masks + self-verifies clean, the
restore-map holds no raw secret, and --restore reverses exactly.

The actual live-transcript sweep is DESTRUCTIVE and stays Steve-gated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: 963c1354-d10a-451f-8e5b-936663056ab7 (yoloforever-night)
0795811 · 2026-09-14 · TK-11683: read-only live-secret scanner for Claude session transcripts
Sweeps ~/.claude/projects/**/*.jsonl for high-confidence live-secret patterns
(reuses the secrets skill's routes.json leak_patterns + adds AKIA/private-key/
gitlab/sendgrid/twilio/bearer/env-key). Closes the gap where cli.js cmdAudit
never scanned the transcript tree. Emits DIGEST-ONLY findings
{file,line,pattern,last4,sha256_16} — never a raw secret value — and a
data/latest.json verdict in the fleet-health PASS/WARN/FAIL vocabulary
(unmeasured input is never a false PASS). Ships --test negative test proving it
FLAGS an injected fake secret + ignores a clean/placeholder line + goes FAIL +
leaks no raw value. Detection logic shared via transcript-secret-lib.mjs so the
(gated) redactor masks exactly what the scanner flags. Scan output dir gitignored.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
cd4cd10 · 2026-09-13 · secrets routes: add govarbitrage as GOOGLE_PLACES_API_KEY fan-out destination
So a future key rotation covers govarbitrage/.env, which was previously missed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G37asNBxx31ZhuCqY5kk46
cc062c2 · 2026-09-12 · TK-11502: register SHOPIFY_ADMIN_ACCESS_TOKEN as managed key (verify=Shopify Admin shop.json), stop TK-10930 drift
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01REdBiwStXHMkuwrHD8Rfzc
287df5a · 2026-09-08 · routes: add DEEPSEEK_API_KEY with DeepSeek balance verify endpoint
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ELf753u6xu7AiZjNRD4yY6
a6259c8 · 2026-07-30 · secrets-manager: fix 2 pre-existing fan bugs (contrarian Hole 4, TK-10045)
- SHOPIFY_ORDERS_TOKEN skill dest used 'path' not 'name' -> fanOut skill branch built skills/undefined/.env (token never reached weekend-csv-products). Fixed to name.
- cmdSync iterated only ROUTES.services, skipping ~37 top-level legacy routes (SHOPIFY_ORDERS_TOKEN, SPOONFLOWER_*, GOOGLE_DRIVE_*, TWILIO_*...) on every sync. Now fans services+top-level = 103 keys.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
f9531b0 · 2026-07-29 · scoping: mark skill .env as review_required (Claude-consumed, not grep-visible) + apply scoped .env to 13 code-scanned non-live projects (TK-10045)
Applied full non-review non-customer-facing batch (Steve-approved), verified each, then ROLLED BACK 12 skills after verify caught that a skill's .env is read by Claude at invoke-time (not a scannable script) — stripping them was unsafe. derive now forces isSkill->review_required so it can't recur. 13 real projects stay scoped (backups .env.pre-scope.* kept).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
a124191 · 2026-07-29 · secrets-manager scoping: fix 3 contrarian-found defects (TK-10045)
- Hole1 (CRITICAL): derive now scans .py (os.environ) + .sh ($VAR) — a Python/shell consumer no longer gets its key stripped on --apply (verified: restaurant-directory GOOGLE_PLACES_API_KEY protected)
- Hole2 (HIGH): scopedSkip fails-open on DSN-driving keys (PG_DW_ADMIN_PASSWORD) + env_file per-dest d.dsn — SCOPED_FANOUT rotation can't drop the DATABASE_URL rewrite
- Hole3: auto-prune ~/.claude.json.bak.* to last 5 (135 secret-bearing copies had piled up in $HOME)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
7795cb8 · 2026-07-29 · secrets-manager: least-privilege scoping (TK-10045) — derive-manifests.js + regen command + manifest-aware fanOut guard (SCOPED_FANOUT-gated)
Blast-radius fix: per-service secret manifests (values-free), regen writes each project a scoped .env = manifest INTERSECT master (remove-only default; --add-missing opt-in), and fanOut skips re-broadening a scoped .env when SCOPED_FANOUT=1. Master .env hard-excluded; review_required (dynamic env access) projects held for hand-review. Dry-run: 67 projects / 111 over-shared keys removable.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
e6f3f31 · 2026-07-21 · Greenland leak cleanup: archive-duplicates script + mirror-orphan backup/plan
143 live '| Greenland' products are stale duplicates of live canonical Phillipe
Romano twins; DTD panel (5/5) ruled ARCHIVE not rename. Script archives them on
the live store + syncs mirror (Steve-gated, dry-run default). 66 mirror-only
orphan rows already deleted locally (reversible; backup TSV included).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
da036c7 · 2026-06-16 · Add automated encrypted off-box backup of secrets master (.env)
Council #1 leftover: secrets-manager/.env had ZERO automated backup (one disk
loss = total secret loss). backup-env.sh: AES256 GPG-symmetric versioned snapshots
in ~/.secrets-backups (last 30), round-trip-verified each run (decrypt==source),
mirrored off-box to iCloud Drive. Passphrase in login Keychain + one-time escrow
handoff. Daily launchd com.steve.secrets-env-backup. Both pass+fail paths proven.
e1b76f7 · 2026-06-11 · retire Desktop secret mirror (~/Desktop/site-factory.env) — DTD verdict A
The Desktop is a high-exposure location (Time Machine / iCloud Desktop-sync /
screenshots) and chmod 600 gives no protection against code running as the user
— the prompt-injection threat that prompted this. The mirror was pure redundancy
with the canonical master at ~/Projects/secrets-manager/.env. fanOut() no longer
writes the Desktop copy; sync verified it is not recreated. KAMATERA_ORIGIN_IP
and ANTHROPIC_API_KEY (previously only on the Desktop) were ingested into master
first so no value was lost.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
41aafea · 2026-06-09 · fix secrets fan: top-level routes invisible (22) + dw_admin never rewrote DATABASE_URL
Root cause of the 2026-06-03 dw_admin rotation half-fire — three stacked bugs,
all fixed in cli.js with ZERO routes.json churn:
1. cli.js read only ROUTES.services[key], but ~22 routes (PG_DW_ADMIN_PASSWORD,
   SHOPIFY_ORDERS_TOKEN, TWILIO_*, GOOGLE_DRIVE_*, ANTHROPIC_*…) live at routes.json
   top-level -> invisible -> fanned 0 destinations. Fix: routeFor() top-level fallback.
2. fanOut had no env_file branch (dw_admin dests' type) -> silently skipped. Added it.
3. fan set a bare *_PASSWORD var, but dw_admin consumers read a full DATABASE_URL DSN.
   Fix: rewriteDsnPassword() + DSN_REWRITE map rewrites the pw inside DATABASE_URL
   for dw_admin (URL-encoding + / =).
Verified: unit + full-branch temp-file tests; route visible (8 dests); routes.json
byte-identical to HEAD. Corrected ROTATION-PRESTAGE.md (real step 3 + prod 3b SSH
step + revert guard). Prod DATABASE_URL still manual (3b).
8b0e8f0 · 2026-06-03 · add rotate-dw-admin-full.sh — complete the forward dw_admin rotation
Console-ready (Steve-run, supervised) script that finishes what ROTATION-PRESTAGE.md
half-did on 2026-06-03: mint new pw (never echoed) -> ALTER dw_admin on Mac2 + prod
-> fan to Mac2 consumers via secrets cli -> in-place DSN rewrite on Kamatera with
.pre-rot.bak backups -> restart ONLY affected apps in batches <=6 (never restart all)
-> converge the 2 split-brain workers -> verify 0 auth failures. --dry-run validated.
4e224ba · 2026-06-03 · secrets viewer: add read-only /rotation page (renders ROTATION-CHECKLIST.md as status cards)
- new /rotation route + markdown→HTML renderer (cards w/ outstanding/done pills, summary counts)
- nav link from main viewer page
- checklist: added items 4 (SHOPIFY_ADMIN_TOKEN burned) + 5 (repl_user pw lost on sub drop)
- page shows key names + mint URLs + route-back commands only — never secret values

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
89bebba · 2026-05-31 · durable daily post-bubbe Tier-1 secret-rotation reminder
LaunchAgent-driven (com.steve.postbubbe-rotation-reminder, 8:37am daily,
survives restarts) replacement for the session-only cron. Compares each
Tier-1 key's registry digest against the 2026-05-31 baseline; a changed
digest = rotated. Fires a macOS notification listing keys still un-rotated,
and SELF-RETIRES (boots out the agent + drops a RESOLVED marker) once all 9
have been rotated. Re-verify + remind only — never rotates console-only keys.

Tracks: the reminder script + the digest baseline (digests are last4:sha-prefix,
not secrets). Plist lives in ~/Library/LaunchAgents (outside the repo).
a1e5d79 · 2026-05-31 · gitignore: add patterns for backup/scratch files (*.bak, *.bak-*, *.pre-*, *.orig etc)
Prevents future accidental commits of routes.json.bak-* and similar
temporary backup files that the secrets-manager tooling generates during
key rotations and audits.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
6033408 · 2026-05-12 · feat(secrets): TMDB_API_KEY + TMDB_READ_ACCESS_TOKEN routes (asseeninmovies/.env)
Both forms (v3 query-param + v4 bearer token) routed to
~/Projects/asseeninmovies/.env. Verify endpoints set to
GET https://api.themoviedb.org/3/authentication (expects success:true)
so paste-then-validate flow works.

Steve to paste either key form; secrets skill auto-routes.
5afad01 · 2026-05-07 · log: 9-domain batch DNS+cert session 2026-05-07
Group A (4 microsites) + Group B (5 typo redirects) fully live on Kamatera with LE SSL.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
f2bf483 · 2026-05-06 · fix: envEscape() so #-containing values keep quotes through sync
Bug: loadEnvFile() strips quotes on read but writeEnvFile()/serializeEnvBody() never re-add them, so any value with a # (e.g. MAILING_ADDRESS="… 15442 Ventura Bl #102 …") gets de-quoted on the next sync and dotenv silently parses only the prefix, fail-closing every gate that depended on the full value.

Symptom in prod (NPH, 2026-05-06): MAILING_ADDRESS sync flipped CAN-SPAM compliance from PASS → no_mailing_address even though the Kamatera .env file looked correct on cat.

Fix: envEscape() wraps any value containing #, quotes, newlines, or edge-whitespace in double quotes (escaping inner quotes/backslashes). Both writeEnvFile() and serializeEnvBody() now run values through it.
e14bede · 2026-05-06 · routes: add NPH (Mac2 + Kamatera) to STRIPE_SECRET_KEY + STRIPE_PUBLISHABLE_KEY fan-out
NPH joins site-factory, lawyer-directory, professional-directory, and the 3
home-history sites on the same live Stripe account fan-out. Marketplace differentiation
remains via application_fee_amount + Stripe Connect destination accounts, not
account-level isolation. Sync ran clean: 122 destination entries written.

(Includes accumulated additions to routes since baseline 05d62f1 — Brave, MOONSHOT,
CF, multiple Stripe variants, Vercel, Purelymail, GoDaddy, Browserbase, Anthropic,
OpenAI, Gemini, Shopify, Resend, restricted-key, DPLA, Gemini-Ralph, ElevenLabs,
Google-Maps, LinkedIn x2, NPH-Google-OAuth x2, GEORGE_AUTH — all already in master
and routed through prior add invocations; this is just the catchup commit.)

File tree

108 files tracked. Click any to browse the source at HEAD.

Other build journals

← Sdcc Mockups  ·  all 4 projects  ·  Security Dashboard →

Export

commits.csv · feed.atom · project.json · commits.json

rendered in 2ms