Fail closed, then explain
Security boundary
The public reviewer is hard-disabled because one required network invariant cannot be proven on the selected runtime.
The blocker is DNS-to-connection pinning
A server can validate DNS answers as public and then call fetch() by hostname. If DNS changes between those moments, the connection may reach a different address. Cloudflare’s resolveOverride is limited to hostnames inside the site’s own zone, so it cannot pin an arbitrary review target. The endpoint therefore returns a versioned disabled result and makes no target request—even if an enable flag is accidentally changed.
Defence sequence in the harness
- Parse a small, exact JSON contract.
- Require HTTPS; reject credentials, fragments, IP literals, special-use names and non-443 ports.
- Validate a single-use Turnstile token server-side.
- Apply a per-client rate gate.
- Resolve A/AAAA and reject any non-public address.
- Resolve again and require the same public address set before the pinned transport.
- Revalidate each redirect, with a maximum of three.
- Accept HTML only within strict time, body and header limits.
Things the reviewer must never do
Network
No target JavaScript, authentication, forms, cookies, user headers, port scanning, vulnerability testing, robots bypass or private resources.
Data
No persistence of target URLs, query strings, bodies, page text, answers, evidence files or reports. No public report URLs or analytics.
Launch gate
A future runtime must prove connection pinning, pass the adversarial suite, receive a dedicated reviewer_sol assessment, and use parent-provisioned Turnstile and rate-limit configuration on an unindexed preview. Until then, no public fetch can be enabled.
Read the public review scope →