Know the boundaries.
The controls implemented for the early-access website, and the protections this implementation does not claim.
Validate before writing.
- Methods & formats
Only POST is accepted. JSON and URL-encoded bodies are supported; unsupported content types receive 415.
- Bounded input
The request stream is counted while reading and rejected after 2,048 bytes. This prevents unbounded body buffering.
- Request origin
A conflicting Origin or cross-site Sec-Fetch-Site is rejected. The form does not expose a cross-origin CORS API. Missing Origin is permitted.
- Field validation
Conservative email syntax, explicit consent and an empty honeypot are checked before the database signup attempt.
- Signup rate control
An atomic D1 counter limits validated attempts, including duplicate emails, to ten per hourly network bucket. The response reports Retry-After when blocked.
- Prepared statements
Values are bound through the D1 binding. Inputs are not concatenated into SQL.
Keep the private part private.
Removal credentials use crypto.getRandomValues(). The database stores their SHA-256 hashes. Duplicate signups do not replace or reveal a credential. Well-formed unknown removal tokens receive the same successful response as a matching token.
Responses disable caching. Error logs use fixed, structured event names and do not include request bodies, email addresses, raw IPs or removal tokens.
The removal link uses a fragment, which is not sent as part of an HTTP request. The token is sent only when the visitor submits the removal form.
Set browser constraints.
Static responses include a Content Security Policy, nosniff, frame denial, a referrer policy and restricted camera, microphone and geolocation permissions. Assets and fonts are hosted with the site.
The current CSP permits inline scripts and styles because the theme boot script and generated page styles use them. It does not claim a nonce-only or hash-only policy.
The management page is marked noindex and uses a no-referrer policy. No third-party analytics or advertising scripts are installed.
These controls have limits.
The implementation does not verify email ownership, send a confirmation email, use a bot challenge, provide authentication or recover lost removal credentials.
Network limits can affect people sharing an address and can be bypassed by distributed clients. The removal endpoint does not use the signup rate limiter. The public signup response distinguishes a new email from an existing one through its status and token field.
No security audit, certification or regulatory approval is claimed. No financial services are implemented here.