Changes touching this path
- Scaffold site/ + wire Vercel #2, loot. subdomain, install proxy (#257)
Thin end-to-end tracer for loot.millerbyte.com (spec docs/specs/loot-site.md
SS1-3): site/ = TanStack Start SSG consuming published @millerbyte/ui@^0.1.0
(theme.css at the root), five placeholder surface routes prerendered, deployed
on Vercel project #2 (root site/) at https://loot.millerbyte.com.
Install proxy: the spec's vercel.json external-rewrite mechanism was falsified
live (Vercel passes GitHub's releases/latest 302 through to the client), so
/install.sh and /install.ps1 are Start server routes that fetch upstream and
stream the bytes back 200 - spec SS2 amended in place.
site/** explicitly public in .lootattributes; .vercelignore allowlists site/
so .loot/ keys and docs/pitch/ can never reach the Vercel builder; site build
artifacts lootignored.
1931146c · dbf3dbe6… - primary catch-up: checkout at the #291 squash (site/ scaffold) folded for the drift reconcile (#297)
e6f7079a · dbf3dbe6…diff - Scaffold site/ + wire Vercel #2, loot. subdomain, install proxy (#257) (#291)
* Scaffold site/ + wire Vercel #2, loot. subdomain, install proxy (#257)
Thin end-to-end tracer for loot.millerbyte.com (spec docs/specs/loot-site.md
SS1-3): site/ = TanStack Start SSG consuming published @millerbyte/ui@^0.1.0
(theme.css at the root), five placeholder surface routes prerendered, deployed
on Vercel project #2 (root site/) at https://loot.millerbyte.com.
Install proxy: the spec's vercel.json external-rewrite mechanism was falsified
live (Vercel passes GitHub's releases/latest 302 through to the client), so
/install.sh and /install.ps1 are Start server routes that fetch upstream and
stream the bytes back 200 - spec SS2 amended in place.
site/** explicitly public in .lootattributes; .vercelignore allowlists site/
so .loot/ keys and docs/pitch/ can never reach the Vercel builder; site build
artifacts lootignored.
Landed via break-glass git branch: the loot-native lane land was blocked by
two live shared-store bugs (review-ferry folds a described WIP into a
reconcile finalize; describe/status disagree on the working change under
concurrent sessions) - tickets to follow.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* Apply #291 review findings
Cache only successful upstream responses in the installer proxy (a transient
GitHub failure must not be CDN-cached for 5 minutes); extract the install
one-liners to one shared module (three copies drifted apart otherwise); fix
the vite.config "fully static" comment and spec SS0 framing to name the two
server-route exceptions; tighten the .lootattributes rationale (the interim
manual deploy is gated by .vercelignore, not the GitHub projection); drop the
cargo-culted overrides block (its pins targeted server deps the site lacks).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Git-Author: Connor Miller <53197564+Connor-Miller@users.noreply.github.com>
231eb5f8diff - resolve conflict at site/src/routes/index.tsx
22825c42 · dbf3dbe6…diff - Author the five surfaces' real content (#259) (#301)
Fill the deployed site/ shells with real content per the loot-site spec section 4:
- Landing: thesis hook + install one-liner + "what works today" loop + three
demo vignettes (private .env / embargo / grant) deep-linking into Docs + CTA row.
- Install: OS-detected default command, 5-native-triple platforms table (v0.1.0),
build-from-source footnote, verify-your-download (checksum + gh attestation,
TLS-only Windows note), troubleshooting. Win ARM64 noted as x64-emulated, not a
native download (#270).
- Docs: getting started (.env quickstart, current verbs), seven distilled core
concepts, four task guides, and a hand-written CLI reference grouped
setup/local/docks/sync/grants/identity - sourced from the binary's usage text
so flags can't drift.
- Why loot: fresh sell-only copy (hook / the claim / why now / grants over
permission bits / proof). No bytes from the sealed docs/pitch/.
- Evidence: proof-log index, one card per committed run over verbatim output
(sealed path, hard embargo, concurrent agents, grant+maroon, amend divergence,
loot-first).
Styling extends styles.css with @millerbyte/ui theme tokens only; nav, footer,
routes, and the install proxy are untouched. tsc clean; all five routes (plus
deep-link hashes) prerender.
Git-Author: Connor Miller <53197564+Connor-Miller@users.noreply.github.com>
e088f034diff - the landing hero becomes the receipt: one published object rendered as the ciphertext this host stores beside the plaintext a key opens, live from the forge, and no panes at all rather than invented ones (#1046)
c729cf41 · dbf3dbe6…diff - the site stops shipping 298 grammars to highlight two languages, and a three-line meta helper stops dragging fifteen more into the entry chunk of every page including the ones with no code at all (#1244)
b06ca1b5 · dbf3dbe6…diff - the landing page leads with the claim and the receipt arrives on scroll: the hero opens on Commit your .env with the mechanism as its subhead, the panes move below the fold as the first thing there, and the three edges and the invite-only paragraph move to the pages where those questions are actually asked
fbdc00bf · dbf3dbe6…diff - the landing page becomes the Deck: the receipt is promoted into the hero as one frame where the ciphertext and the plaintext of the live object share the same lines and a dragged seam cuts between them, a live stats strip follows, the three ideas and the loop and the recipe become a bento, and a closing plate ends the page - superseding the receipt-below-the-fold placement while keeping the pane semantics, re-pointing the measure-cap pin at the seam, and raising every surface ceiling on the record for the shared stylesheet and routes chunk it costs
c25f21d1 · dbf3dbe6…diff - the two claims the Deck put on the front door get the checks they never had: a Rust-side pin fails the moment key_seal stops building the refusal the landing page quotes, and the measure cap reaches the live stats strip by asserting every class it ships is a class the stylesheet knows
d21c0454 · dbf3dbe6…diff - the landing page stops pointing visitors at the relay and stops saying it cannot read what it holds: the check-it-yourself cell ran loot clone https://relay.millerbyte.com and said every sealed object stays sealed in your hands, but a relay holds the key to every Internal object (ADR 0011) and that clone handed this private repo to anyone who ran it (#2388), and the built-with-loot plate said the relay that hosts it physically cannot read the private code it stores. the cell now links to the repo own public tree page on the forge, from the owner and repo the receipt reads (so it renders only when there is a demo to name them), where anyone sees every path and everything but the published files locked, and the plate says the forge that hosts it holds no key to the private code, only to what is published (ADR 0041). FALSIFY and its reasoning are gone; a keyless forge clone earns a 403 under ADR 0061, which is why the check is a page and not a command. site gate green (777 passed), / is 259 bytes lighter; owes a site deploy (#2392)
a30fc440 · dbf3dbe6…diff
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.