The original peerInstances comment framed the two-row pattern as a
band-aid for getOurOrigin's https://${DOMAIN} default. After
investigating a clean collapse to one row (PUBLIC_ORIGIN override on
each spawned instance), the deeper coupling surfaces:
- extractDomain() strips port via new URL().hostname, so unique-port
localhost instances all share hostname '127.0.0.1' and the
receiver's attribution guard
extractDomain(user.homeInstance) === extractDomain(fedHeaders.origin)
becomes ambiguous in any multi-remote configuration.
- The homeInstance validator regex /^[a-zA-Z0-9._-]+$/ in auth.ts
rejects ':', so the port cannot be encoded into homeInstance to
disambiguate.
- Eliminating the second row would require a production refactor of
extractDomain (port-preserving), the attribution check (decoupled
from URL), or the homeInstance validator (allow ':') — all out of
scope.
So the harness DELIBERATELY keeps DOMAIN as a per-instance human label
('home.test.local' / 'remoteN.test.local') for stable identity, and the
two peer rows per direction (transport URL + getOurOrigin URL) are
structural to localhost-port test reality, not a band-aid. Comment
rewritten to reflect this. PUBLIC_ORIGIN remains available in
production code for reverse-proxy / dev-without-TLS deployments.