Server-only provider credentials
쿠팡 파트너스, AdPick, LinkPrice 승인 피드, 해외 보조망과 게시 채널의 인증정보는 브라우저 코드로 전달하지 않습니다. 응답은 서버에서 정규화되고 상태 API는 Secret 값을 반환하지 않습니다.
Fail-closed promotion gate
Live affiliate URLs require valid approved provider credentials and an explicit DEALMINER_PROMOTION_APPROVED=true setting. Scheduled and manual publishing remain disabled when any requirement is missing.
Publisher controls
- Manual publishing requires a server-side bearer token.
- Only a freshly retrieved provider opportunity can be published.
- The destination webhook must use HTTPS.
- Expired, untracked, or low-confidence routes are rejected.
- Affiliate disclosure is attached to every generated payload.
- Outbound routes use HMAC signatures and expire after six hours.
- 해외 실시간 입찰은 국내 원화 EPC를 초과할 때만 사용자 클릭에서 작동합니다.
Input controls
Search queries are bounded to 120 characters and request bodies to 8 KB. Settlement files are limited to 10 MB, parsed in the browser, deduplicated by transaction ID, and never counted when required columns are malformed.
Transport and browser controls
Production traffic uses HTTPS. Responses apply HSTS, Referrer-Policy, MIME-sniffing protection, clickjacking protection, Cross-Origin-Opener-Policy, and a restrictive Permissions-Policy.
Report a vulnerability
Use the support channel with a [SECURITY] prefix. Do not publish keys, tokens, webhook URLs, transaction reports, or personal information.