diff options
Diffstat (limited to 'docs')
| -rw-r--r-- | docs/FUTURE_PROOF.md | 62 | ||||
| -rw-r--r-- | docs/MANAGE.md | 56 |
2 files changed, 118 insertions, 0 deletions
diff --git a/docs/FUTURE_PROOF.md b/docs/FUTURE_PROOF.md new file mode 100644 index 0000000..298dc6a --- /dev/null +++ b/docs/FUTURE_PROOF.md @@ -0,0 +1,62 @@ +# Future Proofing (No Generator) + +This site is intentionally hand-edited PHP. Keep the *style* the same while +making maintenance easier and the surface more resilient. + +## Principles + +- Navigation and core content should work without JavaScript. +- External embeds should always have a plain-link fallback. +- URLs should be stable; if something must move, leave a redirect page. +- Translations follow a consistent naming rule (`_jp.php` / `_zh.php`). +- Secrets stay outside the document root. +- nginx owns security headers (CSP, HSTS, nosniff, Referrer-Policy, Permissions-Policy). + +## What We Have + +### 1) Sitemap and robots.txt + +- `robots.txt` points to `sitemap.xml` and disallows admin/API/tools paths +- `python3 tools/generate_sitemap.py` rebuilds the public crawl map + +### 2) Human-friendly site map + +- `/map/` is a clickable index for humans (with JP/ZH variants) + +### 3) Translation naming convention + +- Default English: `page.php` or `section/index.php` +- Japanese: `page_jp.php` or `section/index_jp.php` +- Simplified Chinese: `page_zh.php` or `section/index_zh.php` +- Strings live in `locales/{en,ja,zh}.php` via `t('key')` + +### 4) Redirect page pattern + +If you rename or move a page, keep an old file that points to the new place. + +Example: + +```php +<?php +header('Location: /new-path/', true, 301); +exit; +``` + +Or a static HTML refresh for pure static drops. + +### 5) Backups and audits + +- `./tools/backup.sh` — tarball (set `BACKUP_DIR`) +- `./tools/run_audits.sh` — link/html/image checks + sitemap regen +- `./tools/uptime_check.sh` — curl probe +- Recommended cron is documented in the root `README.md` + +### 6) Legacy retirement + +- `/mstartpage/` permanently redirects to `/startpage/` + +## Optional next steps + +- Fill remaining locale gaps when shipping new UI strings +- Run `python3 tools/link_rot.py` occasionally for external URLs +- Prefer `password_hash` in `/var/lib/sillylaird/admin_auth.php` over legacy sha256 diff --git a/docs/MANAGE.md b/docs/MANAGE.md new file mode 100644 index 0000000..c8f2537 --- /dev/null +++ b/docs/MANAGE.md @@ -0,0 +1,56 @@ +# Site Management (No Generator) + +This site is hand-edited PHP 8.3 (no framework, no build step). Pages are +plain `.php` files; shared markup lives in `partials/`. + +## Shared assets + +- Global CSS: `/assets/css/site.css` +- Shared JS (menu + language + blog list): `/assets/js/site.js` +- Fonts: `/assets/css/fonts.css` (self-hosted; no Google Fonts) +- Cache busting: `partials/asset_version.php` → `asset_v('assets/css/site.css')` + +## Shared includes + +| Partial | Role | +|---------|------| +| `partials/head_meta.php` | OG / Twitter / canonical / hreflang / favicon / feeds | +| `partials/header.php` | Fixed site header | +| `partials/footer.php` | Footer | +| `partials/i18n.php` | `t($key)` — locale from `_jp` / `_zh` filename suffix | +| `partials/session.php` | Session bootstrap (admin only; no extra security headers) | +| `partials/asset_version.php` | `asset_v()` mtime query strings | + +Pass a `$meta` array then `include` `head_meta.php` (see `links.php` or `now/index.php`). + +## Translations + +- Dicts: `locales/{en,ja,zh}.php` +- Page stubs: `page_jp.php` / `page_zh.php` usually `require` the EN page +- Missing keys fall back to English, then the key string +- EN is the source of truth; keep ja/zh in sync when adding keys + +## SEO / crawl basics + +- `robots.txt` points to `sitemap.xml` and disallows `/admin`, `/api/`, etc. +- Rebuild sitemap: `python3 tools/generate_sitemap.py` +- Nightly: `tools/run_audits.sh` (see root `README.md` cron examples) + +## Admin + +- Login: `/admin/login.php` +- Panel: `/admin.php` (blog, changelog, vibe, now, motd, startpage, journal, guestbook, collection) +- MOTD: `/admin.php?section=motd` writes `motd/motd.json`. waifu (`/opt/waifu-bot`) polls it and posts to `based@conference.sillylaird.ca` (the room, not individual nicks). Public page: `/motd/`. +- Password hash lives **outside** the docroot at `/var/lib/sillylaird/admin_auth.php` + (override with `ADMIN_AUTH_FILE`). Prefer `password_hash` / `password_verify`; + legacy `sha256` + salt still supported. Generate a new hash with + `php /mnt/slab/make_admin_hash.php`. +- Game collection: small-web inventory catalog (photo | `name :: title` | specs). + Public pages: + - `/gaming/collection/` — **Video games** (`videogames[]` systems/consoles) + - `/gaming/collection/tech.php` — **Library** (titles under systems) + - `/gaming/collection/packs.php` — song packs (`online[]`) + - `/gaming/collection/wishlist.php` — Wishlist across all three + Shared: `gaming/collection/_lib.php`. Data: `games.json`. + Admin **Collection**: preview list + CRUD for video games, tech, packs; + photo upload to `gaming/collection/images/`. |
