Independent education

Educational readiness review · not legal advice

Fail closed, then explain

Security boundary

The public reviewer is hard-disabled because one required network invariant cannot be proven on the selected runtime.

Fetch disabled by default and by code

The blocker is DNS-to-connection pinning

A server can validate DNS answers as public and then call fetch() by hostname. If DNS changes between those moments, the connection may reach a different address. Cloudflare’s resolveOverride is limited to hostnames inside the site’s own zone, so it cannot pin an arbitrary review target. The endpoint therefore returns a versioned disabled result and makes no target request—even if an enable flag is accidentally changed.

Defence sequence in the harness

  1. Parse a small, exact JSON contract.
  2. Require HTTPS; reject credentials, fragments, IP literals, special-use names and non-443 ports.
  3. Validate a single-use Turnstile token server-side.
  4. Apply a per-client rate gate.
  5. Resolve A/AAAA and reject any non-public address.
  6. Resolve again and require the same public address set before the pinned transport.
  7. Revalidate each redirect, with a maximum of three.
  8. Accept HTML only within strict time, body and header limits.

Things the reviewer must never do

Network

No target JavaScript, authentication, forms, cookies, user headers, port scanning, vulnerability testing, robots bypass or private resources.

Data

No persistence of target URLs, query strings, bodies, page text, answers, evidence files or reports. No public report URLs or analytics.

Launch gate

A future runtime must prove connection pinning, pass the adversarial suite, receive a dedicated reviewer_sol assessment, and use parent-provisioned Turnstile and rate-limit configuration on an unindexed preview. Until then, no public fetch can be enabled.

Read the public review scope →