Add a document shelf at /documents, served through the app
Files live outside the repo at /srv/scout-website-assets/docs (bind-mounted
read-only at /docs), the same arrangement as the photos, published by a
manifest.json beside them. Adding a document is a file drop plus a manifest
entry - the app re-reads the manifest on mtime change, so no rebuild and no
redeploy.
The manifest maps a stable slug to a filename, so next year's permission slip
can replace this year's without breaking a link already printed on a flyer.
Documents are served through /documents/{slug} rather than from a static
mount, and NOT placed under /app/static, which is public forever. That is the
point: when member login exists it plugs into documents.visible() and no
public URL moves. The visibility field already carries 'members', which today
is hidden from the index and 404s rather than 403s, since a 403 would
advertise a document we cannot yet gate.
This commit is contained in:
@@ -29,9 +29,33 @@ Event fields the feed emits (one object per event):
|
||||
- Past events are hidden from "Next up" automatically; the Calendar page shows the whole program year.
|
||||
- TeamSnap (team 8198615) stays the source of truth for registered families; Radicale `mike/site73` is the source for this public site.
|
||||
|
||||
## Documents
|
||||
|
||||
Files at `/srv/scout-website-assets/docs` (bind-mounted read-only at `/docs`), published by
|
||||
`manifest.json` in that same folder. **Adding a document is a file drop plus a manifest entry: no
|
||||
rebuild, no redeploy.** The app re-reads the manifest whenever its mtime changes.
|
||||
|
||||
```json
|
||||
{"slug": "permission-slip", "file": "2026-permission-slip.pdf",
|
||||
"title": "Activity permission slip", "description": "One per scout, per outing.",
|
||||
"category": "forms", "unit": "both", "visibility": "public", "updated": "2026-08-30"}
|
||||
```
|
||||
|
||||
- `slug` is the permanent URL: `greenlanescouts73.org/documents/<slug>`. **Never change one that has
|
||||
been printed or emailed.** To publish a new version, point the same slug at the new filename.
|
||||
- `category` matches an id in the manifest's `categories`; anything else lands under "Everything else".
|
||||
- `visibility`: `public`, or `members` for later. `members` documents are hidden from the index and
|
||||
return 404 - **this is not a working gate yet**, it is the seam login will attach to.
|
||||
- `updated` optional; without it the file's own mtime is shown.
|
||||
|
||||
Documents are served **through the app** (`/documents/{slug}`), never from a static mount. Anything
|
||||
under `/app/static` is public forever, so nothing that will ever need gating goes there. When member
|
||||
login exists it plugs into `documents.visible()` and no public URL moves.
|
||||
|
||||
## Layout
|
||||
|
||||
- `app/app.py` — FastAPI app, all five pages server-rendered (Home, /cubs, /troop, /calendar?unit=, /join). `/contact` 301s to `/join`.
|
||||
- `app/app.py` — FastAPI app, all pages server-rendered (Home, /cubs, /troop, /calendar?unit=, /join, /documents). `/contact` 301s to `/join`.
|
||||
- `app/documents.py` — the document shelf: manifest loading, the slug-to-file map, and the one visibility gate.
|
||||
- `docker-compose.yml` — Portainer Repository stack definition (port 8131).
|
||||
- Images: **not in the repo.** Bind-mounted read-only from `/srv/scout-website-assets/img`. Source photos live on the NAS (`Scouting-Recruitment-Images`, `scouting-comms/pack-73/assets/social`); web-sized copies in `Scouting-Recruitment-Images/_web`.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user