Repository navigation
feat(store): step a, the request-time platform marker; inside the app no purchase, upgrade or pricing surface and no Google button; gated pages render per request; CI gate verify-platform-gate.mjs - #239
Merged
Conversation
… no purchase, upgrade or pricing surface and no Google button, read per request from KnowFlowApp/<n>; the pages that change on it render per request; gated in CI by verify-platform-gate.mjs Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
🛡️ Fixor Security ReportRepository:
🔒 Analyzed by Fixor · 2026-10-07T10:14:38.124Z |
… stay prerendered on the CDN; the app is rewritten by the middleware to prerendered twins under /<locale>/native/ without the Pricing link and the Google button; measurements and the gate's new rules recorded Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
docs/store/STORE_PATH.mdstep a: the server-side half of the request-time platform marker, and everything that reads it. Step b (the Capacitor config that sends it) only has to setappendUserAgent: 'KnowFlowApp/1'.Rebuilt on the owner's objection (second commit). The first build made the landing, the marketing and legal pages, login and signup render per request for every visitor. Measured on production (five samples each): a CDN-served page answers in 0.18–0.20 s, a function-rendered response in 0.26–0.31 s warm and about 1.0 s cold, and every visit would have been a function invocation against the Hobby allowance (1M invocations, 4 CPU-hours, 360 GB-hours a month; no overage billing, Vercel pauses). The design now:
.next/prerender-manifest.jsonafter the build lists/en/login,/en/signup,/en,/en/privacyand the Arabic ones as before./<locale>/native/(seven bare re-exports under a layout that hides the Pricing link and the Google button). The middleware, which already runs on every request, rewrites an app request to the twin; the URL stays; each variant sits at its own cache key, so noVaryis needed and no bleed is possible. Vercel: Routing Middleware "runs globally before the cache"; Next:NextResponse.rewrite()"automatically propagates the required RSC rewrite headers upstream", so router prefetches land on the twin too. The user agent survives the header stripping of fix(#136): only a page load writes kf-locale; every link that crosses languages is a plain <a> #226/fix(#136): the guard reads what the middleware receives: Sec-Fetch-Dest, else Accept #227.currentPlatform()./pricingredirect to the dashboard for the app; a web visit straight to a/native/path gets the 404 page.The five requirements
hrefis also a webhref; a forged marker in a browser behaves exactly like the app.grepoversrc/, each covered (Section 7 block).scripts/verify-platform-gate.mjsin the requiredtscjob: renders, the real middleware (redirects, rewrites, the 404), and a source scan that fails on an ungated/pricingreference,upgradeHrefor Google start, a predicate fed a literal or nothing,navigator.userAgentin client code, a static page or twin that reads the request, a twin that is not a bare re-export, or a twin missing from the middleware's list. Red on five deliberate breaks; green now. The other 19 proof steps pass locally.Objections recorded
STORE_PATH.mdsaid/refundwould be sent to the app entry; it is a policy page, not a call to action, and is rewritten like the other legal pages. The file is corrected and T2's scope written down exactly.Section 7: one block, additions only (0 deletions). Rows 42, 69, 81 untouched. No schema, grant, auth config, template or env change.
🤖 Generated with Claude Code