Skip to content

feat: infer links regardless of Raider.IO ownership visibility - #34

Merged
Erilla merged 1 commit into
mainfrom
feat/fingerprint-ownership-visibility
Aug 10, 2026
Merged

feat: infer links regardless of Raider.IO ownership visibility#34
Erilla merged 1 commit into
mainfrom
feat/fingerprint-ownership-visibility

Conversation

@Erilla

@Erilla Erilla commented Aug 10, 2026

Copy link
Copy Markdown
Owner

Replaces #33, which was left conflicting after #32 squash-merged. Same single commit, rebased onto main.

The sweep gated both its root and every candidate on ownerId === null — Raider.IO ownership not being publicly linked. That one condition covers two unrelated states:

State characterDetails.user Was it excluded?
Player withheld the ownership link null yes
Character never claimed on Raider.IO null yes

Sampling arbitrary characters found the second state is the ordinary one, and it is exactly the population the fingerprint exists to reach — bank alts and levelling alts are the least likely characters to be claimed upstream. Both gates are removed.

This reverses a closed decision. Privacy stance on defeating hidden ownership resolved that privacy-hidden ownership excludes fingerprint-derived linkage, and Data-protection exposure for publishing derived account linkage named not publishing inferred-only linkage where a contrary preference was signalled as one of the two mitigations that materially move the UK GDPR balancing and necessity tests. A fingerprint-derived link may now connect characters whose Raider.IO ownership is not public. Maintainer's decision; recorded on both issues and on the map.

Also in scope, because the candidate gate was where it lived: each candidate cost one live getCharacter call to Raider.IO — hundreds per sweep, counted against neither the discovery request cap nor the Blizzard hourly budget. Removing the gate removes the call, and a test now pins it.

  • /privacy no longer promises an exclusion the code does not make, and points at removal requests as the only route.
  • The design spec carries a dated amendment; CONTEXT.md redefines privacy-hidden ownership.
  • Suppression checks, including the recheck immediately before admission, are untouched.

Both new handler tests were confirmed red against the previous code.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Qh8Zb2HnaxebWrRLUMoAiv

The sweep gated both its root and every candidate on Raider.IO ownership
being public (`ownerId === null`). That condition cannot tell a player who
withheld the link from a character never claimed on Raider.IO at all, and
it excluded the latter — most characters, and precisely the bank and
levelling alts the fingerprint exists to find.

Maintainer's decision to remove both gates. This reverses the resolution
of "Privacy stance on defeating hidden ownership" (#8) and drops the
behavioural mitigation "Data-protection exposure for publishing derived
account linkage" (#16) identified as the one that materially moves the UK
GDPR balancing and necessity tests. Manual removal requests are now the
only exclusion route, and suppression checks are unchanged.

Removing the candidate gate also removes one unbudgeted Raider.IO request
per roster member — hundreds per sweep, counted against neither the
discovery cap nor the Blizzard hourly budget.

/privacy no longer promises an exclusion the code does not make; the
design spec carries an amendment and CONTEXT.md redefines the term.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qh8Zb2HnaxebWrRLUMoAiv
@Erilla
Erilla merged commit a8bbab2 into main Aug 10, 2026
2 checks passed
@Erilla
Erilla deleted the feat/fingerprint-ownership-visibility branch August 10, 2026 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant