Harden the site: CI, form endpoint, SEO, privacy and accessibility #9
Loading…
Reference in a new issue
No description provided.
Delete branch "site-hardening"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Twelve ticket PRs merged into this branch, each reviewed and green on its own CI run: #5 and #14 CC-7 CI and deploy, #4 and #13 CC-8 SEO and canonical domain, #3 CC-3 dummy register endpoint and thanks page, #6 CC-2 hash-link redirects, #7 and #15 CC-5 privacy notice, #8 CC-9 accessibility pass, #10 CC-13 favicon, #11 CC-4 spam protection, #12 CC-11 How it works and Install copy.
Behavioural changes:
POST /api/registerlogs each submission as one JSON line to stdout and redirects to/thanks; the form works without JavaScript; a filled honeypot is dropped silently and more than five posts a minute from one address get 429.campercan.netis canonical;campercan.ioandwwwhosts 301 to it. Every page has its own title, description, canonical and share tags, plussitemap.xml,robots.txtand a favicon. New/privacypage with contacthello@campercan.net. Skip link, focus rings, nav landmarks, and a slightly darker muted text colour for AA contrast. Old/#/…links redirect to the real pages. How it works and Install have real copy; spec rows stay TBC.Rollout: merging this triggers the new
deployjob, which builds the image and pushesgit.robware.uk/rob/campercan:latest. If the push fails with 401 the automatic token lacks package scope; add a repo secretREGISTRY_TOKENwithwrite:packageand re-run. Then on the host:docker compose pull && docker compose up -d, and point Nginx Proxy Manager at port 34817 with Force SSL and HSTS on.Tested: CI on every merge to this branch (build, html-validate, 16 tests). axe 4.10.2 reports 0 violations on all 12 pages via
test/axe.jslocally. The deploy job itself is untested until the first push to main.