Add unlisted visibility: served by link, off the index, noindex

Internal papers need a durable link before member login exists. 'unlisted'
serves a document at its slug but keeps it off /documents and sends
X-Robots-Tag: noindex so it stays out of search results.

Serving and listing are now separate questions: visible() decides whether a
document can be served at all and stays the seam login attaches to, listed()
decides whether it shows on the index. 'members' remains hidden AND
unservable, so the weaker state cannot be mistaken for the gate.

This is obscurity, not access control, and both the README and the manifest
say so. An unlisted link is forwardable.
This commit is contained in:
Mike Wichers
2026-08-30 09:21:26 -04:00
parent 1ecdb32139
commit 17c4df796a
3 changed files with 34 additions and 12 deletions
+3 -1
View File
@@ -594,8 +594,10 @@ def document_file(slug: str):
</div></div>"""
return HTMLResponse(page("Not found · Pack & Troop 73", body, "docs"), status_code=404)
_, mime = documents.kind(d)
headers = {"X-Robots-Tag": "noindex, nofollow"} if documents.noindex(d) else None
return FileResponse(d["path"], media_type=mime, filename=d["path"].name,
content_disposition_type=documents.disposition(d))
content_disposition_type=documents.disposition(d),
headers=headers)
FAQ = [