aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'README.md')
-rw-r--r--README.md11
1 files changed, 9 insertions, 2 deletions
diff --git a/README.md b/README.md
index c88918c..9c32133 100644
--- a/README.md
+++ b/README.md
@@ -9,6 +9,7 @@ Server-rendered HTML, no JavaScript required, works on old browsers and phones.
- **Design** form: background colour/image, fonts, widths, header, menu position, footer.
- Changes are live immediately: save, then refresh the blog tab.
- A **superadmin** creates bloggers, resets passwords, disables or deletes accounts.
+- The **root domain is itself a blog**, owned by the superadmin and managed like any other.
- Images are stored in Postgres; everything is in one database.
## Local development
@@ -22,7 +23,8 @@ make seed # (another terminal) demo data: superadmin admin/admin, blogger al
Then open:
-- Dashboard: http://blogspace.localhost:8080 (log in as `admin` or `alice`)
+- Root blog (the superadmin's): http://blogspace.localhost:8080 — "Log in" link in its footer
+- Dashboard: http://blogspace.localhost:8080/login (log in as `admin` or `alice`)
- Alice's blog: http://alice.blogspace.localhost:8080
Chrome and Firefox resolve any `*.localhost` name to your machine, so no DNS or
@@ -101,10 +103,15 @@ internal/web/ host router, handlers, templates, static CSS, theme
### How requests are routed
-`Host == BASE_DOMAIN` → management site (`/login`, `/dashboard`, `/b/<sub>/…`, `/admin/`).
+`Host == BASE_DOMAIN` (or `www.`) → management site (`/login`, `/dashboard`, `/b/<sub>/…`, `/admin/`)
+**plus** the root blog's public pages on every other path.
`Host == <sub>.BASE_DOMAIN` → that blog's public pages (`/`, `/<page>`, `/<page>/<post>`, `/feed.xml`, `/media/<id>`).
Anything else → 404.
+The root blog is a normal `blogs` row with subdomain `www`; it is created on first
+start for the first superadmin and managed at `/b/www/`. Page slugs that would be
+shadowed by management routes (`login`, `admin`, `b`, …) are rejected for every blog.
+
### Auth notes
Sessions are HS256 JWTs in an `HttpOnly` cookie. The token carries the user's