Part of #12 (phase 1 of docs/milestones/W1.md): the site's first pages, and the CI split that lets the site change without running the firmware tests and builds.
What's in it
CI split.ci.yml (firmware) skips a change that touches only site/, docs/, README.md or CONTEXT.md, on pushes to main and on pull requests; a tag always runs it. New site.yml runs zola check, zola build (a Zola pinned by its checksum) and site/tools/check_site.py for those files.
The site (site/, Zola): the home page from your design (both themes on the device's palette, notched shapes, self-hosted fonts, wordmark and icons, nine App cards, real screenshots, updates and build sections), an Install page with a browser flasher, and Downloads (the releases, read at build time).
Changed from the design, as agreed: Install first; a "what you need" row and a status box; the mesh messenger is a planned card and nothing promises sending; the latest version comes from the API; "Wiki" is gone; an independence line and a no-cookies, no-third-party-requests statement; and the keyboard focus ring now shows on notched controls.
No third-party requests. Fonts and ESP Web Tools (10.4.0, Apache-2.0, trimmed to the ESP32-S3) are vendored; check_site.py fails the build if a page loads from another origin. The wordmark SVGs' embedded C2PA block is stripped.
site/README.md: how to build, and what the server needs.
Checked
The Site workflow's exact commands in a clean container; 16 browser checks (Chromium) over the home, Downloads, 404 and Install pages, at 1280 and 390 px, including the Install logic with the server's headers simulated, a hostile download URL refused, and the real server's missing CORS header falling back to the esptool steps. Details, and what is not checked, in docs/milestones/W1.md.
For you to do
Caddy, on the git.twis.la block (so the Install page can reach the release API and downloads from the browser):
Tell me when it's in and I'll check it with curl -H "Origin: https://roro9stack.net". Until then the Install page says it can't reach the server and shows the esptool steps.
The web server:roro9stack.net resolves to your server, plain HTTP redirects to HTTPS, and HTTPS has no certificate yet. Pull main and run zola build in site/.
Try the flasher once from Chrome with a real Cardputer. I tested the page's logic, not a flash.
About the runs
This pull request touches both the workflows and the site, so it runs both workflows once each. The CI split itself is first visible on the next change that touches only site/ or docs/.
Part of #12 (phase 1 of `docs/milestones/W1.md`): the site's first pages, and the CI split that lets the site change without running the firmware tests and builds.
## What's in it
- **CI split.** `ci.yml` (firmware) skips a change that touches only `site/`, `docs/`, `README.md` or `CONTEXT.md`, on pushes to `main` and on pull requests; a tag always runs it. New `site.yml` runs `zola check`, `zola build` (a Zola pinned by its checksum) and `site/tools/check_site.py` for those files.
- **The site** (`site/`, Zola): the home page from your design (both themes on the device's palette, notched shapes, self-hosted fonts, wordmark and icons, nine App cards, real screenshots, updates and build sections), an **Install** page with a browser flasher, and **Downloads** (the releases, read at build time).
- Changed from the design, as agreed: Install first; a "what you need" row and a status box; the mesh messenger is a **planned** card and nothing promises sending; the latest version comes from the API; "Wiki" is gone; an independence line and a no-cookies, no-third-party-requests statement; and the keyboard focus ring now shows on notched controls.
- **No third-party requests.** Fonts and ESP Web Tools (10.4.0, Apache-2.0, trimmed to the ESP32-S3) are vendored; `check_site.py` fails the build if a page loads from another origin. The wordmark SVGs' embedded C2PA block is stripped.
- `site/README.md`: how to build, and what the server needs.
## Checked
The Site workflow's exact commands in a clean container; 16 browser checks (Chromium) over the home, Downloads, 404 and Install pages, at 1280 and 390 px, including the Install logic with the server's headers simulated, a hostile download URL refused, and the real server's missing CORS header falling back to the esptool steps. Details, and what is **not** checked, in `docs/milestones/W1.md`.
## For you to do
1. **Caddy, on the `git.twis.la` block** (so the Install page can reach the release API and downloads from the browser):
```caddy
@releases {
method GET HEAD
path /twisla/roro9stack/releases/download/* /api/v1/repos/twisla/roro9stack/releases*
}
header @releases Access-Control-Allow-Origin "https://roro9stack.net"
header @releases Vary Origin
```
Tell me when it's in and I'll check it with `curl -H "Origin: https://roro9stack.net"`. Until then the Install page says it can't reach the server and shows the esptool steps.
2. **The web server:** `roro9stack.net` resolves to your server, plain HTTP redirects to HTTPS, and HTTPS has no certificate yet. Pull `main` and run `zola build` in `site/`.
3. **Try the flasher once from Chrome with a real Cardputer.** I tested the page's logic, not a flash.
## About the runs
This pull request touches both the workflows and the site, so it runs both workflows once each. The CI split itself is first visible on the next change that touches only `site/` or `docs/`.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
site.yml builds the site with a Zola pinned by its checksum and checks the
pages when site/, docs/, README.md or CONTEXT.md change. ci.yml gets
paths-ignore for the same files on pushes to main and on pull requests; a
tag always runs it (Gitea doesn't apply path filters to tags). A change
touching both runs both.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
A Zola site in site/, from the design: both themes on the device's
palette, notched shapes, self-hosted fonts, the wordmark and icons, two
generated hero drawings, nine App cards (the mesh messenger marked
planned), real screenshots, the updates and build sections. The Install
page builds ESP Web Tools' manifest in the browser from the Gitea API (it
needs Caddy to allow the origin), refuses any download that isn't on the
project's server, and falls back to the esptool steps. Downloads lists the
releases. The focus ring shows on notched controls. A page checker fails
the build if a page loads from another origin.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part of #12 (phase 1 of
docs/milestones/W1.md): the site's first pages, and the CI split that lets the site change without running the firmware tests and builds.What's in it
ci.yml(firmware) skips a change that touches onlysite/,docs/,README.mdorCONTEXT.md, on pushes tomainand on pull requests; a tag always runs it. Newsite.ymlrunszola check,zola build(a Zola pinned by its checksum) andsite/tools/check_site.pyfor those files.site/, Zola): the home page from your design (both themes on the device's palette, notched shapes, self-hosted fonts, wordmark and icons, nine App cards, real screenshots, updates and build sections), an Install page with a browser flasher, and Downloads (the releases, read at build time).check_site.pyfails the build if a page loads from another origin. The wordmark SVGs' embedded C2PA block is stripped.site/README.md: how to build, and what the server needs.Checked
The Site workflow's exact commands in a clean container; 16 browser checks (Chromium) over the home, Downloads, 404 and Install pages, at 1280 and 390 px, including the Install logic with the server's headers simulated, a hostile download URL refused, and the real server's missing CORS header falling back to the esptool steps. Details, and what is not checked, in
docs/milestones/W1.md.For you to do
git.twis.lablock (so the Install page can reach the release API and downloads from the browser):curl -H "Origin: https://roro9stack.net". Until then the Install page says it can't reach the server and shows the esptool steps.roro9stack.netresolves to your server, plain HTTP redirects to HTTPS, and HTTPS has no certificate yet. Pullmainand runzola buildinsite/.About the runs
This pull request touches both the workflows and the site, so it runs both workflows once each. The CI split itself is first visible on the next change that touches only
site/ordocs/.🤖 Generated with Claude Code
https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT