Public Wiki Privacy

The public site is an allow-through view of a private repository. Relationship, career, employer-specific, interview, incident, decision, inbox, private research, and operational-log content must not be exposed to locked visitors.

Enforcement Boundary

ui/src/lib/privacy-policy.json is the shared policy source for the runtime and production bundler. ui/src/lib/gating.ts applies it to page, search, graph, embed, asset-API, sitemap, and agent discovery decisions. ui/scripts/bundle-wiki.mjs uses the same manifest when compiling deployment indexes.

The policy is fail-closed:

  • private: true always gates a page.
  • private: false cannot override a protected category, slug, token, or tag.
  • People, career, finance, interview prep, postmortems, decisions, inbox, and private research are gated as categories.
  • The finance category is restricted because provider inventory, retirement plans, benefits elections, insurance state, and tax-source locations are private even when they omit credentials and account identifiers.
  • Generated agent packs and the operational log are gated because they can quote or summarize private source pages.
  • Source-only research may be public only after review and an explicit entry in the shared publicSlugs allowlist; frontmatter cannot grant that exception.
  • A public stable object must not link to a password wall. A reviewed project contract may remove its page-level private: true marker only after private raw captures and personal material are excluded; protected slugs, tokens, tags, and categories still win.
  • Career-bearing USER companion pages are gated individually.
  • The /me portfolio requires the global private session.
  • Private pages are removed from locked search, navigation, graph results, sitemaps, llms.txt, and structured discovery.
  • The production bundle emits only image assets referenced by public pages. Private-only assets are absent from the static deployment rather than relying on an application redirect gate.

Verification

Run:

pnpm --dir ui test:privacy-gating
pnpm --dir ui test:gate-passwords
npm run build

The privacy regression test covers relationship pages, career pages, employer-specific slugs, user-profile pages, and the operational log. A production build additionally proves that the bundler and runtime can consume the shared manifest.

The GitHub repository itself is private. Website gating is still required because the deployed reader intentionally serves a public subset. Source: gh repo view Kevin-Liu-01/Kevin-Wiki --json visibility,isPrivate, 2026-07-14


Timeline