aboutsummaryrefslogtreecommitdiffstats
path: root/docs/FUTURE_PROOF.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/FUTURE_PROOF.md')
-rw-r--r--docs/FUTURE_PROOF.md62
1 files changed, 62 insertions, 0 deletions
diff --git a/docs/FUTURE_PROOF.md b/docs/FUTURE_PROOF.md
new file mode 100644
index 0000000..298dc6a
--- /dev/null
+++ b/docs/FUTURE_PROOF.md
@@ -0,0 +1,62 @@
+# Future Proofing (No Generator)
+
+This site is intentionally hand-edited PHP. Keep the *style* the same while
+making maintenance easier and the surface more resilient.
+
+## Principles
+
+- Navigation and core content should work without JavaScript.
+- External embeds should always have a plain-link fallback.
+- URLs should be stable; if something must move, leave a redirect page.
+- Translations follow a consistent naming rule (`_jp.php` / `_zh.php`).
+- Secrets stay outside the document root.
+- nginx owns security headers (CSP, HSTS, nosniff, Referrer-Policy, Permissions-Policy).
+
+## What We Have
+
+### 1) Sitemap and robots.txt
+
+- `robots.txt` points to `sitemap.xml` and disallows admin/API/tools paths
+- `python3 tools/generate_sitemap.py` rebuilds the public crawl map
+
+### 2) Human-friendly site map
+
+- `/map/` is a clickable index for humans (with JP/ZH variants)
+
+### 3) Translation naming convention
+
+- Default English: `page.php` or `section/index.php`
+- Japanese: `page_jp.php` or `section/index_jp.php`
+- Simplified Chinese: `page_zh.php` or `section/index_zh.php`
+- Strings live in `locales/{en,ja,zh}.php` via `t('key')`
+
+### 4) Redirect page pattern
+
+If you rename or move a page, keep an old file that points to the new place.
+
+Example:
+
+```php
+<?php
+header('Location: /new-path/', true, 301);
+exit;
+```
+
+Or a static HTML refresh for pure static drops.
+
+### 5) Backups and audits
+
+- `./tools/backup.sh` — tarball (set `BACKUP_DIR`)
+- `./tools/run_audits.sh` — link/html/image checks + sitemap regen
+- `./tools/uptime_check.sh` — curl probe
+- Recommended cron is documented in the root `README.md`
+
+### 6) Legacy retirement
+
+- `/mstartpage/` permanently redirects to `/startpage/`
+
+## Optional next steps
+
+- Fill remaining locale gaps when shipping new UI strings
+- Run `python3 tools/link_rot.py` occasionally for external URLs
+- Prefer `password_hash` in `/var/lib/sillylaird/admin_auth.php` over legacy sha256