Description
Three standard site-level documents are missing. All three are cheap, and two of them are already half-built.
1. /.well-known/security.txt (RFC 9116) — 404
A /security page already exists (internal/server/ui_routes.go:15, s.uiSecurityPage) alongside legal/, so the vulnerability-disclosure policy is written but undiscoverable by the tooling and researchers that look for it at the well-known path.
Serve a signed-or-plain security.txt with at least Contact:, Expires:, and Policy: (pointing at /security). Expires is mandatory under RFC 9116 and must be a future date, so it needs either a build-time value or a periodic refresh — decide which and document it, since a stale Expires makes the file non-conforming.
Also serve it at /security.txt (currently 404) since the RFC allows the legacy top-level location as a fallback.
2. /favicon.ico — 404
No favicon exists in internal/server/static/, and templates/shell.html has no <link rel="icon">. Every browser requests /favicon.ico implicitly, so this 404s on every page load for every visitor.
Add an icon to the embedded static FS and reference it from the shell <head>. Serving a real route for /favicon.ico (rather than relying on the implicit lookup) also avoids the request falling into the static handler's edge cases.
3. Web app manifest — 404
internal/server/security_headers.go:6 already declares manifest-src 'self' in the CSP, and the app ships service-worker.js (ui_routes.go:12) plus web push (/settings/push/*). That is a PWA missing only its manifest: the app cannot be installed, and the CSP directive is currently dead.
Add /manifest.webmanifest with name, short name, start URL, display mode, theme colour, and icons, then link it from shell.html. Icons must satisfy img-src 'self'.
Notes
Sequence after the static-handler and NotFound tickets so these routes are written against the corrected route surface rather than the current one.
Tests
Handler tests asserting each path returns 200 with the right content type, and that security.txt parses with a future Expires.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.