diff options
Diffstat (limited to 'docs/FUTURE_PROOF.md')
| -rw-r--r-- | docs/FUTURE_PROOF.md | 62 |
1 files changed, 62 insertions, 0 deletions
diff --git a/docs/FUTURE_PROOF.md b/docs/FUTURE_PROOF.md new file mode 100644 index 0000000..298dc6a --- /dev/null +++ b/docs/FUTURE_PROOF.md @@ -0,0 +1,62 @@ +# Future Proofing (No Generator) + +This site is intentionally hand-edited PHP. Keep the *style* the same while +making maintenance easier and the surface more resilient. + +## Principles + +- Navigation and core content should work without JavaScript. +- External embeds should always have a plain-link fallback. +- URLs should be stable; if something must move, leave a redirect page. +- Translations follow a consistent naming rule (`_jp.php` / `_zh.php`). +- Secrets stay outside the document root. +- nginx owns security headers (CSP, HSTS, nosniff, Referrer-Policy, Permissions-Policy). + +## What We Have + +### 1) Sitemap and robots.txt + +- `robots.txt` points to `sitemap.xml` and disallows admin/API/tools paths +- `python3 tools/generate_sitemap.py` rebuilds the public crawl map + +### 2) Human-friendly site map + +- `/map/` is a clickable index for humans (with JP/ZH variants) + +### 3) Translation naming convention + +- Default English: `page.php` or `section/index.php` +- Japanese: `page_jp.php` or `section/index_jp.php` +- Simplified Chinese: `page_zh.php` or `section/index_zh.php` +- Strings live in `locales/{en,ja,zh}.php` via `t('key')` + +### 4) Redirect page pattern + +If you rename or move a page, keep an old file that points to the new place. + +Example: + +```php +<?php +header('Location: /new-path/', true, 301); +exit; +``` + +Or a static HTML refresh for pure static drops. + +### 5) Backups and audits + +- `./tools/backup.sh` — tarball (set `BACKUP_DIR`) +- `./tools/run_audits.sh` — link/html/image checks + sitemap regen +- `./tools/uptime_check.sh` — curl probe +- Recommended cron is documented in the root `README.md` + +### 6) Legacy retirement + +- `/mstartpage/` permanently redirects to `/startpage/` + +## Optional next steps + +- Fill remaining locale gaps when shipping new UI strings +- Run `python3 tools/link_rot.py` occasionally for external URLs +- Prefer `password_hash` in `/var/lib/sillylaird/admin_auth.php` over legacy sha256 |
