From f0eaf46755e04b806e2df07a2fabd4060a72d54c Mon Sep 17 00:00:00 2001 From: grm Date: Sat, 12 Sep 2026 11:43:14 +0300 Subject: Serve the superadmin's blog on the root domain The base domain (and www.) now serves a regular blog owned by the first superadmin, created automatically on startup, alongside the management routes. Literal management paths take precedence over the blog's page wildcards, and the slugs they would shadow are reserved. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- internal/web/web_test.go | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) (limited to 'internal/web/web_test.go') diff --git a/internal/web/web_test.go b/internal/web/web_test.go index 42e37a7..dcd766c 100644 --- a/internal/web/web_test.go +++ b/internal/web/web_test.go @@ -44,6 +44,26 @@ func TestHostRoutingWithoutDB(t *testing.T) { } } +// On the root domain the literal management routes must win over the blog's /{page} wildcards. +func TestRootRoutePrecedence(t *testing.T) { + cfg := &config.Config{BaseDomain: "example.com", JWTSecret: []byte("x"), MaxUploadBytes: 1 << 20} + s := NewServer(cfg, nil) + for path, want := range map[string]int{"/login": 200, "/healthz": 200, "/dashboard": 303, "/admin/": 303, "/b/alice/posts": 303, "/account/password": 303} { + rec := httptest.NewRecorder() + req := httptest.NewRequest("GET", path, nil) + req.Host = "example.com" + s.ServeHTTP(rec, req) + if rec.Code != want { + t.Errorf("%s: got %d, want %d", path, rec.Code, want) + } + } + for _, slug := range []string{"login", "admin", "b", "media", "feed.xml"} { + if !reservedPageSlugs[slug] { + t.Errorf("page slug %q should be reserved", slug) + } + } +} + func TestThemeNormalizeAndCSS(t *testing.T) { th := ParseTheme([]byte(`{"bg_color":"red;}body{display:none","font":"comic","bg_image":"../etc","nav_position":"left-sidebar"}`)) if th.BgColor != DefaultTheme().BgColor || th.Font != "sans" || th.BgImage != "" || th.NavPosition != "left-sidebar" { -- cgit v1.2.3