diff options
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 11 |
1 files changed, 9 insertions, 2 deletions
@@ -9,6 +9,7 @@ Server-rendered HTML, no JavaScript required, works on old browsers and phones. - **Design** form: background colour/image, fonts, widths, header, menu position, footer. - Changes are live immediately: save, then refresh the blog tab. - A **superadmin** creates bloggers, resets passwords, disables or deletes accounts. +- The **root domain is itself a blog**, owned by the superadmin and managed like any other. - Images are stored in Postgres; everything is in one database. ## Local development @@ -22,7 +23,8 @@ make seed # (another terminal) demo data: superadmin admin/admin, blogger al Then open: -- Dashboard: http://blogspace.localhost:8080 (log in as `admin` or `alice`) +- Root blog (the superadmin's): http://blogspace.localhost:8080 — "Log in" link in its footer +- Dashboard: http://blogspace.localhost:8080/login (log in as `admin` or `alice`) - Alice's blog: http://alice.blogspace.localhost:8080 Chrome and Firefox resolve any `*.localhost` name to your machine, so no DNS or @@ -101,10 +103,15 @@ internal/web/ host router, handlers, templates, static CSS, theme ### How requests are routed -`Host == BASE_DOMAIN` → management site (`/login`, `/dashboard`, `/b/<sub>/…`, `/admin/`). +`Host == BASE_DOMAIN` (or `www.`) → management site (`/login`, `/dashboard`, `/b/<sub>/…`, `/admin/`) +**plus** the root blog's public pages on every other path. `Host == <sub>.BASE_DOMAIN` → that blog's public pages (`/`, `/<page>`, `/<page>/<post>`, `/feed.xml`, `/media/<id>`). Anything else → 404. +The root blog is a normal `blogs` row with subdomain `www`; it is created on first +start for the first superadmin and managed at `/b/www/`. Page slugs that would be +shadowed by management routes (`login`, `admin`, `b`, …) are rejected for every blog. + ### Auth notes Sessions are HS256 JWTs in an `HttpOnly` cookie. The token carries the user's |
