docs(plan): record the org lead's decisions and design against them #2
Reference in New Issue
Block a user
No description provided.
Delete Branch "docs/plan-decisions"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Revision 2 of the design of record. Revision 1 (#1) ended in five open questions; all are answered, so the plan now states decisions and designs against them rather than asking.
What changed
New §5 — decisions of record. Twelve decisions taken by the org lead on 2026-08-19, recorded so they are not re-litigated: the runtime, the beta signup, the scope of the documentation fixes, real screenshots over placeholders, who drafts the legal pages, who deploys, the maturity posture, no analytics, the support channels, keeping the existing emblem, and the demo instance.
New §6–§9, designing against them:
/app/brandresolved per-file against a baked/app/brand-default, served at stable unhashed URLs so Vite cannot fingerprint them. AcheckTokens.mjsfails the build on any colour literal outside the token file, because otherwise "one CSS file changes the appearance" quietly decays into "most of the appearance"./privacyin three separately-scoped sections,/terms, and where the Play Data Safety declaration comes from.§4 Phase 0 grows from the four operator-facing fixes to all ten documentation conflicts, plus retiring the personal Gmail that
docs/SECURITY.mdpublishes as the public vulnerability contact.§15 records the demo instance as planned and out of scope: a Proxmox VM running the full stack including ServUO, restricted and reset hourly. The site reserves its slot now so it costs one line in a bind-mounted file later.
Re-verification, and three things revision 1 got wrong
Every version re-read from the Gitea API on 2026-08-19. Protocol 4, bundle 2026.08.19, sidecar v2.0.0, overlay v1.0.0, installer v0.1.0, module-uo v1.0.1, Android v0.5.0, Module API 1.6.0 — all confirmed. Corrected:
bundlesbranch, not underbundles/. §12's fact-checker would have fetched a 404.websitepublishes no releases at all — it ships as container images. The site must never print a "website version".BaseUrlHolder/HostSelectionInterceptor/ServerPreferencesmean the user enters the address. This is load-bearing for the privacy policy and the Play Data Safety form.Two design notes worth a second opinion
The site sends no email, and that turned out not to block the beta. With Play's email-list method Google does not notify testers either — the developer distributes the opt-in link. But that link only works for addresses already on the tester list, so it is safe to publish: the confirmation screen shows it, and Discord carries the "you've been added" announcement. No SMTP, no deliverability, no unsubscribe machinery for a list nobody is mailed from.
The CSV export is a CLI, not an admin page. An authenticated HTTP surface on a marketing site is a login form, a session and a password to rotate, for an operation performed by the one person who already has shell on the host against a file already on their disk. The site keeps no authenticated surface at all.
Still open (§14) — none of it blocks starting
/privacy; Cloudflare Email Routing is free and the domain is already on Cloudflare. Three forwards proposed:hello@,privacy@,security@.MAX_CREATION_LIMIT = 0as defence in depth, Turnstile on the form./communityis written the same way either way; only one sentence changes.AI-assisted contribution
Drafted by Claude (Claude Code), per the org's AI-usage disclosure policy. Commit carries the
Co-Authored-Bytrailer.