Add unlisted visibility: served by link, off the index, noindex
Internal papers need a durable link before member login exists. 'unlisted' serves a document at its slug but keeps it off /documents and sends X-Robots-Tag: noindex so it stays out of search results. Serving and listing are now separate questions: visible() decides whether a document can be served at all and stays the seam login attaches to, listed() decides whether it shows on the index. 'members' remains hidden AND unservable, so the weaker state cannot be mistaken for the gate. This is obscurity, not access control, and both the README and the manifest say so. An unlisted link is forwardable.
This commit is contained in:
@@ -44,8 +44,13 @@ rebuild, no redeploy.** The app re-reads the manifest whenever its mtime changes
|
||||
- `slug` is the permanent URL: `greenlanescouts73.org/documents/<slug>`. **Never change one that has
|
||||
been printed or emailed.** To publish a new version, point the same slug at the new filename.
|
||||
- `category` matches an id in the manifest's `categories`; anything else lands under "Everything else".
|
||||
- `visibility`: `public`, or `members` for later. `members` documents are hidden from the index and
|
||||
return 404 - **this is not a working gate yet**, it is the seam login will attach to.
|
||||
- `visibility`:
|
||||
- `public` - listed on `/documents`, open to anyone.
|
||||
- `unlisted` - served at its slug to anyone holding the link, kept off the index, sent with
|
||||
`X-Robots-Tag: noindex`. For internal papers that need a durable link before login exists.
|
||||
**This is obscurity, not access control.** An unlisted link is forwardable; assume it will be.
|
||||
- `members` - hidden and unservable, returns 404. **This is not a working gate yet**, it is the
|
||||
seam login will attach to.
|
||||
- `updated` optional; without it the file's own mtime is shown.
|
||||
|
||||
Documents are served **through the app** (`/documents/{slug}`), never from a static mount. Anything
|
||||
|
||||
Reference in New Issue
Block a user