What to build
Today every saved calculation — including the user's purchase cost per pound, which is commercially sensitive — is served unauthenticated to all visitors via the public "Recent Calculations (Community)" feed, with no opt-in and no disclosure at save time.
Decision needed first: is the community feed an intentional product feature? If yes, which fields are acceptable to publish (species/conversion/yield are probably fine; cost probably not), and is sharing opt-in per save or per account?
Then implement: an is_public flag on calculations (defaulting existing rows to private), a disclosure/toggle in the save flow, and a public endpoint that only returns opted-in rows with the approved fields.
Context: AUDIT_REPORT.md §3.4 and task 1.4 (branch claude/repo-audit-improvement-ozhlau); Open Question #2.
Acceptance criteria
Blocked by
None - can start immediately (decision first, then implementation)
What to build
Today every saved calculation — including the user's purchase cost per pound, which is commercially sensitive — is served unauthenticated to all visitors via the public "Recent Calculations (Community)" feed, with no opt-in and no disclosure at save time.
Decision needed first: is the community feed an intentional product feature? If yes, which fields are acceptable to publish (species/conversion/yield are probably fine; cost probably not), and is sharing opt-in per save or per account?
Then implement: an
is_publicflag on calculations (defaulting existing rows to private), a disclosure/toggle in the save flow, and a public endpoint that only returns opted-in rows with the approved fields.Context: AUDIT_REPORT.md §3.4 and task 1.4 (branch
claude/repo-audit-improvement-ozhlau); Open Question #2.Acceptance criteria
Blocked by
None - can start immediately (decision first, then implementation)