trackslash
TRACK-63 P3

Add password-manager well-knowns and an app-served robots.txt

0
All issues

Description

Three small discovery documents the app should own. All currently missing or outside our control.

1. /.well-known/change-password — 404

W3C "A Well-Known URL for Changing Passwords". Password managers use it to deep-link users straight to password rotation. The app already has the destination: POST /settings/password and POST /settings/password-login (internal/server/ui_routes.go:48-49).

Implementation is a 303 to /settings. Note the spec's companion requirement: /.well-known/resource-that-should-not-exist-whose-status-code-should-not-be-200 must not return 200, otherwise managers assume the site 200s everything and ignore the well-known. That works today only because unmatched paths 404 — worth an explicit test so the NotFound ticket cannot silently break it.

2. /.well-known/passkey-endpoints — 404

The app supports passkeys (/settings/passkeys/*, ui_routes.go:56-59, plus passkey login and signup). This well-known lets credential managers point users at the passkey management UI.

Serve JSON with an enroll URL and a manage URL, both pointing into /settings.

3. App-served robots.txt

https://trackslash.com/robots.txt currently returns 200, but it is Cloudflare's auto-injected content-signals boilerplate — entirely comments, with no User-agent: or Disallow: lines. There is no route for it in mountUIRoutes, so the app expresses no crawl policy at all.

Serve our own. The portal is almost entirely auth-gated, so the useful policy is: disallow the app surface (/settings, /tokens, /login, /signup, /me, project routes), and allow the public preview project referenced in README.md:22. Decide whether to preserve Cloudflare's content-signal comments when overriding — dropping them silently changes the AI-training/search signals currently published.

Skipping sitemap.xml deliberately: with the portal auth-gated it would cover a single public project and is not worth maintaining yet.

Tests

Assert /.well-known/change-password redirects to /settings, that the sentinel path does not return 200, that passkey-endpoints returns valid JSON, and that robots.txt is served by the app rather than falling through.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.