Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
547 commits
Select commit Hold shift + click to select a range
367a593
Merge remote GAM attribution spec
prk-Jr Aug 15, 2026
78107e6
Merge GAM cohort attribution implementation
prk-Jr Aug 15, 2026
fb07665
Merge branch 'main' into feature/ts-cli-ad-templates
prk-Jr Aug 15, 2026
5420390
Sync EdgeZero to latest deploy-actions tip and adopt config gc
aram356 Aug 15, 2026
acca2dd
Re-merge PR #940: Sync EdgeZero to latest deploy-actions tip and adop…
aram356 Aug 15, 2026
b23f270
Merge remote-tracking branch 'origin/main' into worktree-edgezero-316…
aram356 Aug 15, 2026
f2a5eb8
Re-merge PR #940 after syncing it with main (which now carries #992 a…
aram356 Aug 15, 2026
1e3edc7
Merge origin/rc/202608 (ESI #1013, GPT diagnostics slot size #1032, m…
aram356 Aug 16, 2026
fe5767e
Sync EdgeZero to deploy-actions tip 5f3d648c
aram356 Aug 16, 2026
cc0126e
Re-merge PR #940: Sync EdgeZero to deploy-actions tip 5f3d648c
aram356 Aug 16, 2026
31de3f6
Fix ad-template CLI section rendering and harden the audit commands
prk-Jr Aug 17, 2026
07b37a1
Verify generated ad-template config before it replaces the operator file
prk-Jr Aug 17, 2026
e7f8268
Add multi-page collection and crawl planning for ad-template generate
prk-Jr Aug 17, 2026
73ac39c
Accumulate cross-page slot evidence for ad-template generate
prk-Jr Aug 17, 2026
f32a1ac
Infer section ad-unit templates from cross-page evidence
prk-Jr Aug 17, 2026
deced19
Let the ad-template writer express section policy and per-section pat…
prk-Jr Aug 17, 2026
6722e19
Crawl site sections in ad-template generate and write inferred templates
prk-Jr Aug 17, 2026
d9133f2
Add device-profile cross-checking to ad-template generate
prk-Jr Aug 17, 2026
2ea48e0
Document ad-template slot generation
prk-Jr Aug 17, 2026
90bc61e
Report why a crawled page yielded no ad slots
prk-Jr Aug 17, 2026
b8a5e5c
Pace the ad-template crawl and allow a headful browser
prk-Jr Aug 17, 2026
142e384
Answer consent APIs and report GPT state during ad-template generate
prk-Jr Aug 17, 2026
f5c8616
Audit through a proxy and collapse lowercase React div-id tokens
prk-Jr Aug 17, 2026
230958b
Refuse ad-template slots that are one placement under per-render div ids
prk-Jr Aug 17, 2026
64b9414
Document the ad-template crawl options added after the first draft
prk-Jr Aug 17, 2026
5156908
Merge branch 'main' into 1014-gpt-diagnostics-doc-completeness
prk-Jr Aug 17, 2026
866bcd4
Merge branch 'main' into feat/admin-ec-lookup-endpoint
prk-Jr Aug 17, 2026
253ff9c
Merge #1025 1014-gpt-diagnostics-doc-completeness into rc/202608
prk-Jr Aug 17, 2026
0fb0cbb
Merge remote-tracking branch 'origin/main' into feat/ssat-debug-comme…
prk-Jr Aug 17, 2026
7d2ba2d
Revise SSAT debug comment sensitivity model
prk-Jr Aug 17, 2026
a04f47d
Merge #1034 docs/gam-ts-cohort-attribution-spec into rc/202608
prk-Jr Aug 17, 2026
3715f27
Tighten SSAT debug metadata privacy model
prk-Jr Aug 17, 2026
b8b917e
Merge #928 feat/admin-ec-lookup-endpoint into rc/202608
prk-Jr Aug 17, 2026
8a61578
Validate redacted SSAT metadata by schema
prk-Jr Aug 17, 2026
de3db0a
Clarify SSAT upstream safety contract
prk-Jr Aug 17, 2026
1af743c
Update SSAT debug comment implementation plan
prk-Jr Aug 17, 2026
691706d
Merge #823 feature/ts-cli-ad-templates into rc/202608
prk-Jr Aug 17, 2026
e7f057d
Correct SSAT implementation verification plan
prk-Jr Aug 17, 2026
a99033f
Fix SSAT plan metadata type handling
prk-Jr Aug 17, 2026
9825743
Harden SSAT debug comment configuration modes
prk-Jr Aug 17, 2026
567c963
Enforce SSAT debug response metadata schemas
prk-Jr Aug 17, 2026
737c18a
Document SSAT debug sensitivity modes
prk-Jr Aug 17, 2026
d7737d3
Implement configurable cache header policies
ChristianPavilonis Jul 8, 2026
d6328f4
Format cache configuration docs
ChristianPavilonis Jul 8, 2026
0e413c2
Address cache policy review feedback
ChristianPavilonis Jul 15, 2026
2de213d
Fix cache policy clippy warnings
ChristianPavilonis Jul 17, 2026
d6920d4
Fix publisher test cache policy argument
ChristianPavilonis Jul 29, 2026
3b9063f
Preserve integration configuration values on rebase
ChristianPavilonis Jul 29, 2026
f4169fb
Harden configurable asset cache rules
ChristianPavilonis Jul 30, 2026
56083e3
Improve publisher HTML cache policy when SSAT is inactive
ChristianPavilonis Aug 6, 2026
d7bfa92
Document dedicated server-side ad template switch
ChristianPavilonis Aug 6, 2026
e9a55d4
Add dedicated server-side ad template switch
ChristianPavilonis Aug 6, 2026
03e429a
Address cache policy review feedback
ChristianPavilonis Aug 13, 2026
38c9636
Preserve origin cache privacy on inactive templates
ChristianPavilonis Aug 17, 2026
fd6d832
Resolve cache policy review feedback
ChristianPavilonis Aug 17, 2026
fefe73a
Merge remote-tracking branch 'origin/pr/1033' into rc/202608
ChristianPavilonis Aug 17, 2026
49061aa
Merge remote-tracking branch 'origin/pr/860' into rc/202608
ChristianPavilonis Aug 17, 2026
0e1a405
Document admin diagnostics review fixes
prk-Jr Aug 18, 2026
ec8ca8c
Clarify admin authentication probes
prk-Jr Aug 18, 2026
2ec38e7
Plan admin diagnostics review fixes
prk-Jr Aug 18, 2026
e637524
Fail closed for concrete admin routes
prk-Jr Aug 18, 2026
539beba
Deny admin diagnostics in publisher fallback
prk-Jr Aug 18, 2026
17f0ac4
Keep admin diagnostics out of publisher fallback
prk-Jr Aug 18, 2026
4657cbf
Keep admin EID diagnostics read only
prk-Jr Aug 18, 2026
63e39b8
Preserve raw admin EC diagnostic records
prk-Jr Aug 18, 2026
178e2cd
Document admin EC and EID diagnostics
prk-Jr Aug 18, 2026
c70de71
Fix admin diagnostic test lint
prk-Jr Aug 18, 2026
69e1b8a
Reserve the full admin fallback namespace
prk-Jr Aug 18, 2026
9841fcc
Collect the root page on every device profile
prk-Jr Aug 18, 2026
8f5b345
Design SSAT debug comment output formatting
prk-Jr Aug 18, 2026
0565947
Plan SSAT debug comment output formatting
prk-Jr Aug 18, 2026
2050f18
Configure SSAT debug comment output format
prk-Jr Aug 18, 2026
00a969a
Pretty print SSAT debug comment dumps
prk-Jr Aug 18, 2026
e4c52a8
Document SSAT debug comment formatting
prk-Jr Aug 18, 2026
ccda520
Format SSAT debug comment implementation plan
prk-Jr Aug 18, 2026
67d1608
Document SSAT auction debug comment usage
prk-Jr Aug 18, 2026
2f4e77e
Merge #943 feat/ssat-debug-comment-config into rc/202608
prk-Jr Aug 18, 2026
cd24192
Document PR 823 review resolution design
prk-Jr Aug 18, 2026
4b779ce
Clarify PR review resolution design
prk-Jr Aug 18, 2026
f3cb010
Plan PR 823 review resolution
prk-Jr Aug 18, 2026
bca89ef
Align ad stack gate diagnostics with runtime
prk-Jr Aug 18, 2026
1b418cc
Match ad template verification to runtime behavior
prk-Jr Aug 18, 2026
1c2dfeb
Define ad template CLI assertion contracts
prk-Jr Aug 18, 2026
e8fb2ee
Bound browser ad template evidence collection
prk-Jr Aug 18, 2026
6a64d0d
Share browser sessions across ad template audits
prk-Jr Aug 18, 2026
0ca3395
Preserve ad template crawl evidence
prk-Jr Aug 18, 2026
dfbc7c8
Make ad template updates transaction-safe
prk-Jr Aug 18, 2026
64a88fa
Document and enforce ad template audit contracts
prk-Jr Aug 18, 2026
af32498
Fix ad template design whitespace
prk-Jr Aug 18, 2026
f536381
Simplify legacy audit dispatch
prk-Jr Aug 18, 2026
37f135a
docs: plan pre-navigation cookie fix
prk-Jr Aug 18, 2026
a58cfcf
Fix pre-navigation audit cookies
prk-Jr Aug 18, 2026
cb0e62f
docs: plan contiguous generated slots
prk-Jr Aug 18, 2026
3707672
Keep generated ad slots contiguous
prk-Jr Aug 18, 2026
a6a87ce
Format docs
prk-Jr Aug 18, 2026
a603e98
Merge branch 'rc/202608' of github.com:IABTechLab/trusted-server into…
ChristianPavilonis Aug 18, 2026
bf9cfdd
Revert "Merge remote-tracking branch 'origin/pr/1033' into rc/202608"
ChristianPavilonis Aug 18, 2026
3953cd6
Reapply "Merge remote-tracking branch 'origin/pr/1033' into rc/202608"
ChristianPavilonis Aug 18, 2026
104d163
Revert "Reapply "Merge remote-tracking branch 'origin/pr/1033' into r…
ChristianPavilonis Aug 18, 2026
f082560
Merge branch 'main' into rc/202608
aram356 Aug 18, 2026
e79cccb
Merge branch 'main' into feat/admin-ec-lookup-endpoint
aram356 Aug 18, 2026
45c7ccd
Merge branch 'main' into feat/ssat-debug-comment-config
aram356 Aug 18, 2026
e8c0eec
Merge branch 'main' into 1009-esi-cacheable-root-spec
aram356 Aug 18, 2026
7c865ce
Merge branch 'main' into refactor/cache-headers
aram356 Aug 18, 2026
1a2d16c
Document comprehensive PR 928 review fixes
prk-Jr Aug 19, 2026
cf25efb
Plan comprehensive PR 928 review fixes
prk-Jr Aug 19, 2026
f3776a9
Keep Fastly admin EC lookups read only
prk-Jr Aug 19, 2026
de61c43
Validate mixed-case admin EC auth coverage
prk-Jr Aug 19, 2026
8649b43
Explain dropped admin EID preview sources
prk-Jr Aug 19, 2026
1198eb9
Share core request cookie extraction
prk-Jr Aug 19, 2026
a3a0479
Harden admin diagnostic responses
prk-Jr Aug 19, 2026
be434c2
Clarify admin diagnostics contracts
prk-Jr Aug 19, 2026
436e25f
Tighten admin diagnostic review coverage
prk-Jr Aug 19, 2026
b8568f3
Resolve ad-template CLI review findings
prk-Jr Aug 19, 2026
efad9c9
Polish ad-template generator output
prk-Jr Aug 19, 2026
bd052b4
Show ad-template generation progress
prk-Jr Aug 19, 2026
1d4ac66
Avoid duplicate crawl failure output
prk-Jr Aug 19, 2026
eb61c86
Plan volatile div collision refusal
prk-Jr Aug 19, 2026
daae07b
Refuse ambiguous volatile ad slots
prk-Jr Aug 19, 2026
cc16ddd
Refuse known volatile ad slot family
prk-Jr Aug 19, 2026
e8f4593
Merge branch 'main' into feature/ts-cli-ad-templates
prk-Jr Aug 19, 2026
02597cf
Document PR 1013 review remediation
prk-Jr Aug 19, 2026
9419424
Clarify PR 1013 remediation outcomes
prk-Jr Aug 19, 2026
8101248
Plan PR 1013 review remediation
prk-Jr Aug 19, 2026
47a58a8
Make Fastly template cache reads fallible
prk-Jr Aug 19, 2026
7329ed8
Preserve injection for unsupported encodings
prk-Jr Aug 19, 2026
df35e79
Scope terminal privacy to synthesized responses
prk-Jr Aug 19, 2026
752fbf3
Refuse publisher ESI and seam collisions
prk-Jr Aug 19, 2026
b3ae41f
Validate and version-guard the SSAT debug comment options
prk-Jr Aug 19, 2026
5491204
Harden template cache boundaries
prk-Jr Aug 19, 2026
341bd52
Make initial GPT scheduling one-shot
prk-Jr Aug 19, 2026
eb8e57a
Remove ESI spike residue
prk-Jr Aug 19, 2026
d0c3cb7
Align ESI spike documentation and tooling
prk-Jr Aug 19, 2026
379c33d
Fix ESI design whitespace
prk-Jr Aug 19, 2026
24a855b
Design template cache terminology rename
prk-Jr Aug 19, 2026
e935e14
Use synthetic fixtures for per-render slot tests
prk-Jr Aug 19, 2026
09b7e4a
Accept a same-host HTTPS upgrade during slot generation
prk-Jr Aug 19, 2026
7d21559
Plan template cache terminology rename
prk-Jr Aug 19, 2026
c2cd68c
Name template cache namespace and diagnostics
prk-Jr Aug 19, 2026
ced398b
Clarify template cache documentation
prk-Jr Aug 19, 2026
ca4f249
Describe shared templates consistently
prk-Jr Aug 19, 2026
1969dff
Fix template cache rustdoc reference
prk-Jr Aug 19, 2026
424af92
Rename template cache local harness
prk-Jr Aug 19, 2026
0a59c92
Use template cache terminology in documentation
prk-Jr Aug 19, 2026
99fb7ca
Clarify template cache documentation
prk-Jr Aug 19, 2026
1680e0a
Document template cache migration exceptions
prk-Jr Aug 19, 2026
4b8e04e
Add APS publisher rendering experiment
ChristianPavilonis Aug 19, 2026
e9bf8f2
Merge commit 'refs/pull/1024/head' of github.com:IABTechLab/trusted-s…
ChristianPavilonis Aug 19, 2026
e2f1f63
Document trusted client IP header design
prk-Jr Aug 19, 2026
d940723
Clarify trusted header validation
prk-Jr Aug 19, 2026
932b9f8
Plan trusted client IP implementation
prk-Jr Aug 19, 2026
209bea2
Ignore local worktrees
prk-Jr Aug 19, 2026
3d542ff
Add trusted client IP configuration
prk-Jr Aug 19, 2026
6b7db93
Differentiate trusted client IP header errors
prk-Jr Aug 19, 2026
01c2c47
Resolve authenticated forwarded client IP
prk-Jr Aug 19, 2026
6314947
Use resolved client IP for middleware geo
prk-Jr Aug 19, 2026
6078a46
Inject APS publisher-native runner
ChristianPavilonis Aug 19, 2026
bf2d1b2
Preserve authoritative client IP absence
prk-Jr Aug 19, 2026
99f8311
Document trusted client IP forwarding
prk-Jr Aug 19, 2026
5cb94e6
Clarify trusted header name restrictions
prk-Jr Aug 19, 2026
53dbaee
Clarify Fastly client IP sanitization order
prk-Jr Aug 19, 2026
caf4422
Reserve the full admin namespace at the fallback boundary
prk-Jr Aug 19, 2026
8684e1b
Require prefix-level admin EC auth coverage
prk-Jr Aug 19, 2026
41484a7
Merge commit '4b8e04e41d2b9b85ff9b12471ba0eb79c0f4f9fa' into rc/20260…
ChristianPavilonis Aug 19, 2026
800e40f
Strengthen trusted client IP shared secret validation
prk-Jr Aug 19, 2026
7d4da82
Strip client-supplied X-Forwarded-For at the edge
prk-Jr Aug 19, 2026
87d9697
Resolve the trusted client IP behind one sanitizing call
prk-Jr Aug 19, 2026
9a1cba9
Mark diagnostics responses terminal-private
prk-Jr Aug 19, 2026
82db770
Anchor the shared seam to the parsed body end
prk-Jr Aug 19, 2026
9e95dd8
Merge branch 'fix/1013-diagnostics-privacy' into 1009-esi-cacheable-r…
prk-Jr Aug 19, 2026
ce9c3c6
Merge branch 'fix/1013-structural-seam-and-meta-csp' into 1009-esi-ca…
prk-Jr Aug 19, 2026
fc969ce
Merge branch 'main' into worktree-edgezero-316-upgrade
aram356 Aug 19, 2026
1aefb13
Merge branch 'rc/202608-pr-1024' into rc/202608
ChristianPavilonis Aug 19, 2026
915ee6f
Merge branch 'main' into issue-1007-cache-control
aram356 Aug 20, 2026
f73a4f5
docs: design round 3 review remediation
prk-Jr Aug 20, 2026
6ee9c16
Merge branch 'main' into feature/ts-cli-ad-templates
prk-Jr Aug 20, 2026
6275d60
docs: refine round 3 remediation design
prk-Jr Aug 20, 2026
d8cc3e8
Plan round 3 review remediation
prk-Jr Aug 20, 2026
e707758
Ignore agent implementation worktrees
prk-Jr Aug 20, 2026
c6c184f
Merge branch 'main' into feat/ssat-debug-comment-config
prk-Jr Aug 20, 2026
6ed133a
Keep page bids responses terminal private
prk-Jr Aug 20, 2026
8abf9ae
Preserve initial ad scheduler latch across handoff
prk-Jr Aug 20, 2026
c8671cc
Cancel invalid template cache reservations
prk-Jr Aug 20, 2026
733b660
Close template cache review gaps
prk-Jr Aug 20, 2026
e2ef9f2
Mark page bids response as must use
prk-Jr Aug 20, 2026
b836fad
Resolve round-4 review on ad-template generation
prk-Jr Aug 20, 2026
a8694da
Clarify trusted client IP secret validation
prk-Jr Aug 20, 2026
57c0aa6
Merge remote-tracking branch 'origin/main' into fix/trusted-client-ip…
prk-Jr Aug 20, 2026
b0c88ab
Validate trusted client IP shared secrets
prk-Jr Aug 20, 2026
78c0db4
Template a slot that never appears on the site root
prk-Jr Aug 20, 2026
2a7052e
Record trusted client IP verification
prk-Jr Aug 20, 2026
84b84c3
Scope the retired admin keys reservation to its own namespace
prk-Jr Aug 20, 2026
2cd4826
Clarify forwarded client IP header guidance
prk-Jr Aug 20, 2026
6fb4238
Merge branch 'main' into feat/admin-ec-lookup-endpoint
prk-Jr Aug 20, 2026
c01d7ac
Merge branch 'main' into 1009-esi-cacheable-root-spec
prk-Jr Aug 20, 2026
6751750
Merge remote-tracking branch 'origin/main' into rc/202608
prk-Jr Aug 20, 2026
06b0df8
Restore upstream publisher behavior and harden cache policies
ChristianPavilonis Aug 20, 2026
49e7094
Address GPT diagnostics review feedback
ChristianPavilonis Aug 20, 2026
9c1b236
Merge current main into cache policy branch
ChristianPavilonis Aug 20, 2026
d909f1b
Merge remote-tracking branch 'origin/pr/928' into rc/202608
ChristianPavilonis Aug 20, 2026
00b4de3
Merge remote-tracking branch 'origin/pr/940' into rc/202608
ChristianPavilonis Aug 20, 2026
53fd5f7
Merge remote-tracking branch 'origin/pr/943' into rc/202608
ChristianPavilonis Aug 20, 2026
fcfce2f
Merge remote-tracking branch 'origin/pr/1032' into rc/202608
ChristianPavilonis Aug 20, 2026
31f718b
Merge remote-tracking branch 'origin/pr/823' into rc/202608
ChristianPavilonis Aug 20, 2026
e44b03e
Merge remote-tracking branch 'origin/pr/860' into rc/202608
ChristianPavilonis Aug 20, 2026
a9a9c0a
Merge branch 'main' into experiment/aps-native-rendering
aram356 Aug 20, 2026
19034b2
Switch esi dependency to released crates.io 0.7.2
prk-Jr Aug 20, 2026
0bd1c7c
Merge remote-tracking branch 'origin/pr/1008' into rc/202608
ChristianPavilonis Aug 20, 2026
073d564
Merge branch 'main' into feature/ts-cli-ad-templates
aram356 Aug 20, 2026
46b7052
Merge branch 'main' into worktree-edgezero-316-upgrade
aram356 Aug 20, 2026
1c60e69
Merge remote-tracking branch 'origin/pr/1013' into rc/202608
ChristianPavilonis Aug 20, 2026
6c416e6
Format configuration guide
ChristianPavilonis Aug 20, 2026
d8499bb
Prevent shared caching of inactive publisher HTML
ChristianPavilonis Aug 20, 2026
76f0372
Merge remote-tracking branch 'origin/main' into issue-1007-cache-control
ChristianPavilonis Aug 20, 2026
2234e9b
Remove legacy C2 harness from release CI
prk-Jr Aug 20, 2026
6b70c8b
remove fastly staging requirement for datadome blockage
ChristianPavilonis Aug 20, 2026
247cfd6
Merge branch 'rc/202608' of github.com:IABTechLab/trusted-server into…
ChristianPavilonis Aug 20, 2026
5d03b77
Harden trusted client IP header handling
prk-Jr Aug 20, 2026
47faca4
Merge branch 'experiment/aps-native-rendering' into rc/202608
ChristianPavilonis Aug 20, 2026
63370fc
Prevent APS creative frame scrollbars
ChristianPavilonis Aug 20, 2026
d4cd2cc
Prevent APS creative frame scrollbars
ChristianPavilonis Aug 20, 2026
f90f638
Pin edgezero dependencies to immutable rev instead of branch
aram356 Aug 21, 2026
bf47680
Document new CLI lifecycle and config gc commands
aram356 Aug 21, 2026
40dd9b3
Drop stale EdgeZero v0.0.4 qualifiers from env-overlay docs
aram356 Aug 21, 2026
e080e6e
Clarify trusted client IP VCL setup
prk-Jr Aug 21, 2026
e3d0312
Document PR 823 round-five review resolution
prk-Jr Aug 21, 2026
d215554
Plan PR 823 round-five review resolution
prk-Jr Aug 21, 2026
76c337e
Preserve generation browser option contracts
prk-Jr Aug 21, 2026
75afced
Protect borrowed section templates during generation
prk-Jr Aug 21, 2026
28ae90c
Clarify audit generation diagnostics
prk-Jr Aug 21, 2026
364c1d2
Pin audit evidence recognition invariants
prk-Jr Aug 21, 2026
e17ddc1
Align ad-template generation documentation
prk-Jr Aug 21, 2026
543e45a
Satisfy borrowed template inference lint
prk-Jr Aug 21, 2026
78a0a0b
Wire browser settle defaults to the correct commands
prk-Jr Aug 21, 2026
33a654e
Merge branch 'main' into feature/ts-cli-ad-templates
prk-Jr Aug 21, 2026
16473c7
Merge branch 'main' into rc/202608
prk-Jr Aug 21, 2026
558bd68
Merge branch 'main' into 1009-esi-cacheable-root-spec
prk-Jr Aug 21, 2026
ab4abcb
Merge branch 'main' into fix/trusted-client-ip-header
prk-Jr Aug 21, 2026
f77e0a2
Merge #1048 remote-tracking branch 'origin/pr/1048' into rc/202608
prk-Jr Aug 21, 2026
69b30c0
Harden APS publisher-native rendering
ChristianPavilonis Aug 21, 2026
13a6ecf
Merge branch 'main' into experiment/aps-native-rendering
ChristianPavilonis Aug 21, 2026
8927e13
Preserve inactive cache policy across revalidation
ChristianPavilonis Aug 21, 2026
cf353e3
Merge main into rc/202608
ChristianPavilonis Aug 21, 2026
59dddff
Merge #823 into rc/202608
ChristianPavilonis Aug 21, 2026
d68b78c
Merge #940 into rc/202608
ChristianPavilonis Aug 21, 2026
4865d4f
Merge #1013 into rc/202608
ChristianPavilonis Aug 21, 2026
393f72f
Merge #1008 into rc/202608
ChristianPavilonis Aug 21, 2026
57591af
Merge #1042 into rc/202608
ChristianPavilonis Aug 21, 2026
58532d7
Remove duplicate APS runner helper after RC merge
ChristianPavilonis Aug 21, 2026
eaa86c2
Merge main into rc/202608
prk-Jr Aug 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 7 additions & 2 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -230,9 +230,14 @@ jobs:
run: |
cargo clippy --manifest-path crates/trusted-server-cli/Cargo.toml --target "$(rustc -vV | sed -n 's/host: //p')" --all-targets -- -D warnings

- name: Set up Chrome for browser fixture tests
id: setup-chrome
uses: browser-actions/setup-chrome@v1

- name: cargo test
run: |
cargo test --manifest-path crates/trusted-server-cli/Cargo.toml --target "$(rustc -vV | sed -n 's/host: //p')"
run: ./scripts/test-cli.sh
env:
CHROME: ${{ steps.setup-chrome.outputs.chrome-path }}

test-typescript:
name: vitest
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,7 @@ src/*.html

/guest-profiles
/benchmark-results/**
/.worktrees/

# Playwright browser tests
/crates/trusted-server-integration-tests/browser/node_modules/
Expand Down
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
### Changed

- **Breaking** — Admin Basic-auth coverage now includes `GET /_ts/admin/ec`, `GET /_ts/admin/ec/{id}`, and `GET /_ts/admin/eids`. Existing configurations whose `[[handlers]]` patterns protect only the key-management endpoints now fail startup; broaden coverage before deploying, preferably with a namespace-boundary pattern such as `^/_ts/admin(?:/|$)`. Coverage of the dynamic `/_ts/admin/ec/{id}` route is no longer inferred from ID-shaped samples: the router accepts any segment after `/_ts/admin/ec/` and Basic Auth runs on the raw path before routing, so patterns anchored to the EC ID grammar (for example `^/_ts/admin/ec/[a-f0-9]{64}[.][A-Za-z0-9]{6}$`) are rejected in favor of a prefix-level matcher. Placeholder and well-known weak handler passwords (`changeme`, `password`, `admin`, `replace-with-…`) now fail startup on every handler rather than only on handlers inferred to cover an admin endpoint, because first-match-wins handler selection lets a narrow handler shadow the admin namespace.
- Publisher HTML uses the browser-only `Cache-Control: private, max-age=60` policy for successful GET document responses and their `304 Not Modified` revalidations when server-side ad templates are structurally inactive, while preserving origin `private`/`no-store` policies and request-scoped bot, prefetch, or consent-denied responses. The `private` directive prevents shared caches that use `Cache-Control` from storing the document. Cookie-bearing responses using the generated inactive policy are finalized as `private, max-age=0`; CDN-specific cache headers remain unchanged and continue to control supporting CDNs independently. Set `[creative_opportunities].enabled = false` to disable publisher HTML and SPA template delivery without disabling direct `POST /auction` callers; an absent configuration, an unmatched slot, or a disabled auction also make the stack structurally inactive. An explicit `enabled = false` is not compatible with older binaries: restore the default, re-push and finalize the config before rolling back.
- **Breaking** — Replaced the legacy APS contextual integration with APS OpenRTB at `/e/pb/bid`. APS configuration now uses canonical `account_id` (`pub_id` remains a compatibility alias), no longer requires APS-specific slot IDs, and defaults script creative eligibility off. Operators must update the endpoint, disable native APS demand for Trusted Server cohorts, and prepare GAM/Universal Creative targeting for `hb_bidder=aps` before rollout. `aps` entries in Prebid bidder lists are logged and stripped. APS renderer winners now preserve the upstream bid `id`, omit `crid` when APS omits it, and carry `ext.trusted_server.renderer` instead of `adm`; external `/auction` consumers must support this response shape.
- **Breaking** — All auction paths now forward only a validated publisher-owned page URL as `site.page`, removing query and fragment data. APS OpenRTB omits `site.ref`; the existing Prebid Server path continues to forward the browser `Referer` as `site.ref`. Query-driven sites may lose contextual targeting and per-page reporting signals that previously came from query parameters.
- Publisher HTML now uses `Cache-Control: max-age=60` when server-side ad templates are inactive, while preserving origin `private`/`no-store` policies and CDN-specific cache headers. Set `[creative_opportunities].enabled = false` to disable publisher HTML and SPA template delivery without disabling direct `POST /auction` callers.
- **Breaking** — `bid_param_zone_overrides` inner values must now be JSON objects; previously non-object or empty values (`"header" = "x"`, `"header" = {}`) were accepted and silently produced a dead rule at runtime. They now fail at startup with a configuration error. Operators upgrading should audit their `bid_param_zone_overrides` config for non-object zone entries.
- **Breaking** — Integration configuration strings are no longer globally reinterpreted as JSON scalars. Operators upgrading should audit `[integrations.*]` settings and use native TOML/typed-config booleans and numbers (for example, `enabled = true`, not `enabled = "true"`); quoted numeric and boolean scalars now fail validation instead of silently converting.
- **Breaking** — Sourcepoint browser module inclusion now requires explicit `[integrations.sourcepoint].enabled = true`; operators relying on the previous unconditional Sourcepoint module should enable the integration before upgrading.
Expand Down
56 changes: 43 additions & 13 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

14 changes: 8 additions & 6 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -54,12 +54,12 @@ criterion = { version = "0.5", default-features = false, features = ["cargo_benc
derive_more = { version = "2.0", features = ["display", "error"] }
directories = "5"
ed25519-dalek = { version = "2.2", features = ["rand_core"] }
edgezero-adapter-axum = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.4", default-features = false }
edgezero-adapter-cloudflare = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.4", default-features = false }
edgezero-adapter-fastly = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.4", default-features = false }
edgezero-adapter-spin = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.4", default-features = false }
edgezero-cli = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.4" }
edgezero-core = { git = "https://github.com/stackpop/edgezero", tag = "v0.0.4", default-features = false }
edgezero-adapter-axum = { git = "https://github.com/stackpop/edgezero", rev = "5f3d648c3c6c38fc6e6b22b5c65c66177363aad8", default-features = false }
edgezero-adapter-cloudflare = { git = "https://github.com/stackpop/edgezero", rev = "5f3d648c3c6c38fc6e6b22b5c65c66177363aad8", default-features = false }
edgezero-adapter-fastly = { git = "https://github.com/stackpop/edgezero", rev = "5f3d648c3c6c38fc6e6b22b5c65c66177363aad8", default-features = false }
edgezero-adapter-spin = { git = "https://github.com/stackpop/edgezero", rev = "5f3d648c3c6c38fc6e6b22b5c65c66177363aad8", default-features = false }
edgezero-cli = { git = "https://github.com/stackpop/edgezero", rev = "5f3d648c3c6c38fc6e6b22b5c65c66177363aad8" }
edgezero-core = { git = "https://github.com/stackpop/edgezero", rev = "5f3d648c3c6c38fc6e6b22b5c65c66177363aad8", default-features = false }
env_logger = "0.11"
error-stack = "0.6"
esi = "0.7.2"
Expand Down Expand Up @@ -96,6 +96,7 @@ scraper = "0.24.0"
serde = { version = "1.0", features = ["derive"] }
serde_json = "1.0.149"
sha2 = "0.10.9"
similar = "2.7"
simple_logger = "5"
spin-sdk = { version = "~6.0", default-features = false, features = ["http", "key-value", "variables"] }
subtle = "2.6"
Expand All @@ -108,6 +109,7 @@ tokio-rustls = "0.26"
toml = "1.1"
toml_edit = "0.23.10"
tower = "0.4"
tracing = "0.1"
trusted-server-core = { path = "crates/trusted-server-core" }
trusted-server-js = { path = "crates/trusted-server-js" }
trusted-server-openrtb = { path = "crates/trusted-server-openrtb" }
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ ts config init
ts config validate

# Audit a public page with Chrome/Chromium to bootstrap a draft config
ts audit https://publisher.example
ts audit generate https://publisher.example

# Run tests (Fastly/WASM crates — requires Viceroy)
cargo test-fastly
Expand Down
61 changes: 59 additions & 2 deletions crates/trusted-server-adapter-axum/src/middleware.rs
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ use edgezero_core::http::{HeaderValue, Response};
use edgezero_core::middleware::{Middleware, Next};
use trusted_server_core::auth::enforce_basic_auth;
use trusted_server_core::constants::HEADER_X_GEO_INFO_AVAILABLE;
use trusted_server_core::http_util::sanitize_trusted_client_ip_headers;
use trusted_server_core::settings::Settings;

// ---------------------------------------------------------------------------
Expand Down Expand Up @@ -35,7 +36,11 @@ impl FinalizeResponseMiddleware {

#[async_trait(?Send)]
impl Middleware for FinalizeResponseMiddleware {
async fn handle(&self, ctx: RequestContext, next: Next<'_>) -> Result<Response, EdgeError> {
async fn handle(&self, mut ctx: RequestContext, next: Next<'_>) -> Result<Response, EdgeError> {
sanitize_trusted_client_ip_headers(
ctx.request_mut(),
self.settings.trusted_client_ip.as_ref(),
);
let mut response = next.run(ctx).await?;
apply_finalize_headers(&self.settings, &mut response);
Ok(response)
Expand Down Expand Up @@ -111,15 +116,35 @@ pub(crate) fn apply_finalize_headers(settings: &Settings, response: &mut Respons
mod tests {
use super::*;

use std::collections::HashMap;
use std::sync::Mutex;

use edgezero_core::body::Body;
use edgezero_core::http::response_builder;
use edgezero_core::context::RequestContext;
use edgezero_core::http::{Method, request_builder, response_builder};
use edgezero_core::middleware::Next;
use edgezero_core::params::PathParams;
use futures::executor::block_on;
use trusted_server_core::redacted::Redacted;
use trusted_server_core::settings::TrustedClientIpConfig;

fn empty_response() -> Response {
response_builder()
.body(Body::empty())
.expect("should build empty test response")
}

fn empty_ctx() -> RequestContext {
let req = request_builder()
.method(Method::GET)
.uri("/test")
.header("x-reader-ip", "198.51.100.7")
.header("x-reader-ip-auth", "fictional-shared-secret-0123456789")
.body(Body::empty())
.expect("should build test request");
RequestContext::new(req, PathParams::new(HashMap::new()))
}

fn settings_with_response_headers(headers: Vec<(&str, &str)>) -> Settings {
let mut s = Settings::from_toml(
r#"
Expand Down Expand Up @@ -197,4 +222,36 @@ mod tests {
"should apply operator-configured response headers"
);
}

#[test]
fn finalize_middleware_strips_configured_trust_headers_before_routing() {
let mut settings = settings_with_response_headers(vec![]);
settings.trusted_client_ip = Some(TrustedClientIpConfig {
ip_header: "x-reader-ip".to_owned(),
auth_header: "x-reader-ip-auth".to_owned(),
shared_secret: Redacted::new("fictional-shared-secret-0123456789".to_owned()),
});
let middleware = FinalizeResponseMiddleware::new(Arc::new(settings));
let observed = Arc::new(Mutex::new(None));
let handler_observed = Arc::clone(&observed);
let handler = Arc::new(move |ctx: RequestContext| {
let handler_observed = Arc::clone(&handler_observed);
async move {
*handler_observed.lock().expect("should lock observation") = Some((
ctx.request().headers().contains_key("x-reader-ip"),
ctx.request().headers().contains_key("x-reader-ip-auth"),
));
Ok::<Response, EdgeError>(empty_response())
}
});

block_on(middleware.handle(empty_ctx(), Next::new(&[], &*handler)))
.expect("should run middleware");

assert_eq!(
*observed.lock().expect("should lock observation"),
Some((false, false)),
"should remove both configured trust headers before the handler"
);
}
}
Loading
Loading