Content fingerprint for legal packages

FeatureDocsService
Shipped
August 6, 2026 at 1:50 PM UTC
Author
Kamo
Commit
6a3e390

Binder.dateUpdated never moves after INSERT, so a package's content has no change signal to compare. Adds a SHA-256 over the canonical ordered binder/item tuple — including imgDatId, because saveImgContent repoints the same Img at new bytes on every Docs save — plus the attestation text hash. Encoding is length-prefixed so a crafted configJson cannot forge a different layout. Also adds com.kamo.z.shared.hr.legal to the repository scan.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing