Validate before storing.
Both endpoints enforce POST, accepted content types and a bounded request-body read. A supplied mismatched Origin or cross-site Sec-Fetch-Site is rejected. Origin checks protect browser flows; they are not authentication for non-browser clients.
Signup adds email and consent checks, a honeypot and an atomic hourly rate counter. Database statements bind values as parameters rather than combining user input into SQL.
The frontend renders server messages as text. The native HTML confirmation includes internally controlled copy and a generated hexadecimal token; it does not reflect a visitor’s email into HTML.
Possession is the removal permission.
A removal credential is generated from 32 bytes of cryptographically secure randomness using Web Crypto. Only its SHA-256 hash is stored. A duplicate signup cannot replace or retrieve the original credential.
Anyone holding that private token can remove its matching signup. Keep it out of logs, screenshots, analytics, query strings and shared messages. The management route sends no referrer and requests no indexing.
The website does not currently provide account-based recovery or email-based token recovery. A lost credential cannot be reconstructed from its hash.
Browser-side controls.
Static responses set a Content Security Policy, X-Content-Type-Options: nosniff, X-Frame-Options: DENY, a referrer policy and a permissions policy disabling camera, microphone and geolocation.
The current CSP limits resource loading to the site, with data images allowed. Inline scripts and styles are permitted for the existing theme initialization and generated styles. This is not a nonce-only or hash-only CSP.
API responses are not cached and use Referrer-Policy: no-referrer. The successful native HTML response also sets a restrictive CSP. Static Pages header rules and API response headers are configured separately.
Know the boundaries.
- The service does not verify email ownership. An email address passing validation may still be undeliverable or belong to someone else.
- The signup endpoint has basic abuse resistance. It does not use Turnstile or another bot-challenge service.
- New and duplicate JSON responses differ. The endpoint does not conceal whether an email is already on the list.
- The removal endpoint does not share the signup rate limiter. Its credential is the authorization mechanism.
- No financial-account authentication, payment processing, custody or asset transfers are implemented.
- No security certification or independent audit is claimed by these docs.
Application error logs record event names, without request bodies, email addresses or raw removal credentials. Cloudflare’s hosting and network logs are separate from application logging.