Add Zapier interface simulator, tree-node Merkle lookups, and user docs
Some checks are pending
offline / test (push) Waiting to run
Some checks are pending
offline / test (push) Waiting to run
In-process trace console validates hops, faults, recoveries, and suggested changes before zapier-platform push. User guide covers signup through central-chain and bulk-summary tree-node hash lookup.
This commit is contained in:
parent
3daa88866d
commit
f3dc0e6eee
56 changed files with 2341 additions and 8 deletions
9
packages/zapier-user-docs/12-security.md
Normal file
9
packages/zapier-user-docs/12-security.md
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
# 12. Security: what Zapier never sees
|
||||
|
||||
- Zapier **never** connects to NATS, tree nodes, WORM archives, or `api.veraetime.net`.
|
||||
- NS1 `nats-server` stays on **127.0.0.1:4222**. Operators use `scripts/nats-tunnel.sh`; it is not a public bind.
|
||||
- File bytes and private metadata never go on chain. Private metadata is only on authenticated archive replies.
|
||||
- API keys are `x-api-key` / Bearer tokens on HTTPS. Treat them like passwords; regenerating kills old Zaps.
|
||||
- Bloom filters are **not** an access-control list. On a hit, middleware still checks tenant/share before returning private records.
|
||||
|
||||
If a trace (simulator or `DEBUG_VERAE`) ever shows a `zapier-platform-app` hop with a `verae.*` subject, that is a bug — do not push the app.
|
||||
Loading…
Add table
Add a link
Reference in a new issue