Description
r.Head("/", ...) at internal/server/ui_routes.go:11 is the only HEAD registration. chi's Get() registers GET only — it does not imply HEAD.
Steps to reproduce
HEAD /login, HEAD /terms, HEAD /{owner}/projects/{key}/sprint, HEAD /{owner}/issues/{key}-1.
Actual
405 with an empty body — the route node exists but the method endpoint is nil.
Expected
200 with headers and no body. Link-preview crawlers, uptime checks, and curl -I all currently fail against every page but the root.
Supporting evidence
internal/server/auth.go:150 explicitly whitelists http.MethodHead for anonymous public-project reads. That branch is unreachable today, which indicates HEAD was intended to work.
Fix
Add middleware that rewrites HEAD→GET and discards the body, or register r.Method(http.MethodHead, ...) alongside the GET registrations. Also add "HEAD" to the CORS AllowedMethods (see the CORS PUT ticket).
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.