Site: roro9stack.net phase 1 (home, Install with a browser flasher, Downloads), and a CI split for site changes #61

Merged
twisla merged 6 commits from site into main 2026-10-06 16:33:07 +00:00
Owner

Part of #12 (phase 1 of docs/milestones/W1.md): the site's first pages, and the CI split that lets the site change without running the firmware tests and builds.

What's in it

  • CI split. ci.yml (firmware) skips a change that touches only site/, docs/, README.md or CONTEXT.md, on pushes to main and on pull requests; a tag always runs it. New site.yml runs zola check, zola build (a Zola pinned by its checksum) and site/tools/check_site.py for those files.
  • The site (site/, Zola): the home page from your design (both themes on the device's palette, notched shapes, self-hosted fonts, wordmark and icons, nine App cards, real screenshots, updates and build sections), an Install page with a browser flasher, and Downloads (the releases, read at build time).
  • Changed from the design, as agreed: Install first; a "what you need" row and a status box; the mesh messenger is a planned card and nothing promises sending; the latest version comes from the API; "Wiki" is gone; an independence line and a no-cookies, no-third-party-requests statement; and the keyboard focus ring now shows on notched controls.
  • No third-party requests. Fonts and ESP Web Tools (10.4.0, Apache-2.0, trimmed to the ESP32-S3) are vendored; check_site.py fails the build if a page loads from another origin. The wordmark SVGs' embedded C2PA block is stripped.
  • site/README.md: how to build, and what the server needs.

Checked

The Site workflow's exact commands in a clean container; 16 browser checks (Chromium) over the home, Downloads, 404 and Install pages, at 1280 and 390 px, including the Install logic with the server's headers simulated, a hostile download URL refused, and the real server's missing CORS header falling back to the esptool steps. Details, and what is not checked, in docs/milestones/W1.md.

For you to do

  1. Caddy, on the git.twis.la block (so the Install page can reach the release API and downloads from the browser):
    @releases {
        method GET HEAD
        path /twisla/roro9stack/releases/download/* /api/v1/repos/twisla/roro9stack/releases*
    }
    header @releases Access-Control-Allow-Origin "https://roro9stack.net"
    header @releases Vary Origin
    
    Tell me when it's in and I'll check it with curl -H "Origin: https://roro9stack.net". Until then the Install page says it can't reach the server and shows the esptool steps.
  2. The web server: roro9stack.net resolves to your server, plain HTTP redirects to HTTPS, and HTTPS has no certificate yet. Pull main and run zola build in site/.
  3. Try the flasher once from Chrome with a real Cardputer. I tested the page's logic, not a flash.

About the runs

This pull request touches both the workflows and the site, so it runs both workflows once each. The CI split itself is first visible on the next change that touches only site/ or docs/.

🤖 Generated with Claude Code

https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT

Part of #12 (phase 1 of `docs/milestones/W1.md`): the site's first pages, and the CI split that lets the site change without running the firmware tests and builds. ## What's in it - **CI split.** `ci.yml` (firmware) skips a change that touches only `site/`, `docs/`, `README.md` or `CONTEXT.md`, on pushes to `main` and on pull requests; a tag always runs it. New `site.yml` runs `zola check`, `zola build` (a Zola pinned by its checksum) and `site/tools/check_site.py` for those files. - **The site** (`site/`, Zola): the home page from your design (both themes on the device's palette, notched shapes, self-hosted fonts, wordmark and icons, nine App cards, real screenshots, updates and build sections), an **Install** page with a browser flasher, and **Downloads** (the releases, read at build time). - Changed from the design, as agreed: Install first; a "what you need" row and a status box; the mesh messenger is a **planned** card and nothing promises sending; the latest version comes from the API; "Wiki" is gone; an independence line and a no-cookies, no-third-party-requests statement; and the keyboard focus ring now shows on notched controls. - **No third-party requests.** Fonts and ESP Web Tools (10.4.0, Apache-2.0, trimmed to the ESP32-S3) are vendored; `check_site.py` fails the build if a page loads from another origin. The wordmark SVGs' embedded C2PA block is stripped. - `site/README.md`: how to build, and what the server needs. ## Checked The Site workflow's exact commands in a clean container; 16 browser checks (Chromium) over the home, Downloads, 404 and Install pages, at 1280 and 390 px, including the Install logic with the server's headers simulated, a hostile download URL refused, and the real server's missing CORS header falling back to the esptool steps. Details, and what is **not** checked, in `docs/milestones/W1.md`. ## For you to do 1. **Caddy, on the `git.twis.la` block** (so the Install page can reach the release API and downloads from the browser): ```caddy @releases { method GET HEAD path /twisla/roro9stack/releases/download/* /api/v1/repos/twisla/roro9stack/releases* } header @releases Access-Control-Allow-Origin "https://roro9stack.net" header @releases Vary Origin ``` Tell me when it's in and I'll check it with `curl -H "Origin: https://roro9stack.net"`. Until then the Install page says it can't reach the server and shows the esptool steps. 2. **The web server:** `roro9stack.net` resolves to your server, plain HTTP redirects to HTTPS, and HTTPS has no certificate yet. Pull `main` and run `zola build` in `site/`. 3. **Try the flasher once from Chrome with a real Cardputer.** I tested the page's logic, not a flash. ## About the runs This pull request touches both the workflows and the site, so it runs both workflows once each. The CI split itself is first visible on the next change that touches only `site/` or `docs/`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
twisla added 5 commits 2026-10-06 16:20:36 +00:00
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
site.yml builds the site with a Zola pinned by its checksum and checks the
pages when site/, docs/, README.md or CONTEXT.md change. ci.yml gets
paths-ignore for the same files on pushes to main and on pull requests; a
tag always runs it (Gitea doesn't apply path filters to tags). A change
touching both runs both.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
A Zola site in site/, from the design: both themes on the device's
palette, notched shapes, self-hosted fonts, the wordmark and icons, two
generated hero drawings, nine App cards (the mesh messenger marked
planned), real screenshots, the updates and build sections. The Install
page builds ESP Web Tools' manifest in the browser from the Gitea API (it
needs Caddy to allow the origin), refuses any download that isn't on the
project's server, and falls back to the esptool steps. Downloads lists the
releases. The focus ring shows on notched controls. A page checker fails
the build if a page loads from another origin.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
W1: what was built and checked in phase 1; the site in the README
Site / build (pull_request) Successful in 8s
CI / build (pull_request) Successful in 8m27s
6680b752af
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
twisla added 1 commit 2026-10-06 16:32:07 +00:00
Site: the build goes to public/ at the repository root, which git ignores
Site / build (pull_request) Successful in 8s
CI / build (pull_request) Canceled after 38s
9415c62132
output_dir in site/config.toml, so zola build in site/ and zola --root site
build from the root both write ./public. The ignore is /public/, not
site/public/.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
twisla merged commit 821949e3f8 into main 2026-10-06 16:33:07 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: twisla/roro9stack#61