From 15c08af28d80695c1d9bb763772fc0c358c0688f Mon Sep 17 00:00:00 2001 From: "pr-automation-bot-public[bot]" Date: Fri, 25 Sep 2026 14:13:47 +0000 Subject: [PATCH] chore: sync static-site docs to dfinity/certified-assets 853c291 --- .sources/upstream.json | 2 +- .../guides/frontends/static-site/access-protection.md | 4 ++-- docs/guides/frontends/static-site/headers.md | 4 ++-- docs/guides/frontends/static-site/how-it-works.md | 11 ++++++----- docs/guides/frontends/static-site/overview.md | 4 ++-- docs/guides/frontends/static-site/redirects.md | 4 ++-- docs/guides/frontends/static-site/routing.md | 4 ++-- docs/guides/frontends/static-site/site-files.md | 4 ++-- .../frontends/static-site/verifying-contents.md | 4 ++-- 9 files changed, 21 insertions(+), 20 deletions(-) diff --git a/.sources/upstream.json b/.sources/upstream.json index bf40a958..5b46e51e 100644 --- a/.sources/upstream.json +++ b/.sources/upstream.json @@ -52,7 +52,7 @@ "synced": [ { "repo": "dfinity/certified-assets", - "pinned": "v0.4.0", + "pinned": "853c291", "source": "docs/", "target": "docs/guides/frontends/static-site/", "script": "scripts/sync-static-site.mjs", diff --git a/docs/guides/frontends/static-site/access-protection.md b/docs/guides/frontends/static-site/access-protection.md index f4548570..c027dfc2 100644 --- a/docs/guides/frontends/static-site/access-protection.md +++ b/docs/guides/frontends/static-site/access-protection.md @@ -4,7 +4,7 @@ description: "Put a login page in front of a private or preview site with revoca sidebar: order: 6 source_repo: "dfinity/certified-assets" -source_ref: "v0.4.0" +source_ref: "853c291" --- By default every deployed app is public. **Access protection** puts a login screen @@ -197,4 +197,4 @@ makes), unauthorized visitors can't pull your content. But: Use it to keep a preview or in-progress app out of public view, not to protect secrets from a determined adversary. - + diff --git a/docs/guides/frontends/static-site/headers.md b/docs/guides/frontends/static-site/headers.md index 7a915dfd..45a45810 100644 --- a/docs/guides/frontends/static-site/headers.md +++ b/docs/guides/frontends/static-site/headers.md @@ -4,7 +4,7 @@ description: "The _headers file: cache-control, security headers, content types, sidebar: order: 4 source_repo: "dfinity/certified-assets" -source_ref: "v0.4.0" +source_ref: "853c291" --- Add a file named `_headers` to the root of your asset directory to attach response @@ -137,4 +137,4 @@ immediately. This list is intentionally conservative and may be relaxed in future releases; it's easier to allow a header later than to start rejecting one that sites already rely on. - + diff --git a/docs/guides/frontends/static-site/how-it-works.md b/docs/guides/frontends/static-site/how-it-works.md index 30e2f269..219ac6bd 100644 --- a/docs/guides/frontends/static-site/how-it-works.md +++ b/docs/guides/frontends/static-site/how-it-works.md @@ -4,7 +4,7 @@ description: "How the canister certifies responses, serves large assets, negotia sidebar: order: 8 source_repo: "dfinity/certified-assets" -source_ref: "v0.4.0" +source_ref: "853c291" --- You don't need any of this to use certified-assets; the [overview](overview.md) is @@ -67,9 +67,10 @@ outlived the problem they solved, and survive mainly as a debugging aid. This canister never needed the escape hatch. It is v2-only and certifies everything, so it behaves identically on both hostnames: it attaches the certificate either way, and on -`raw` the gateway simply discards it. Nothing about the canister's guarantee weakens -there, but the client has chosen a party that doesn't check, so it gets no better -assurance than from an ordinary web host. +`raw` the gateway forwards it without checking it. Nothing about the canister's guarantee +weakens there, but the client has chosen a party that doesn't check, so unless it +verifies the certificate itself, it gets no better assurance than from an ordinary web +host. **The canister can't reliably refuse `raw` requests.** Its only clue is the `Host` header, which the client supplies and nothing authenticates. Matching it against `raw` @@ -170,4 +171,4 @@ in-place upgrade that keeps all state, while a **breaking** release reinstalls a fresh sync re-uploads everything. See [Releasing](https://github.com/dfinity/certified-assets/blob/main/README.md#releasing) for the details. - + diff --git a/docs/guides/frontends/static-site/overview.md b/docs/guides/frontends/static-site/overview.md index eed9e2de..e6dd40ff 100644 --- a/docs/guides/frontends/static-site/overview.md +++ b/docs/guides/frontends/static-site/overview.md @@ -4,7 +4,7 @@ description: "Deploy a built frontend, docs, or any folder of files to a caniste sidebar: order: 1 source_repo: "dfinity/certified-assets" -source_ref: "v0.4.0" +source_ref: "853c291" --- Deploy a **static site** (a built frontend, docs, or any folder of files) to a @@ -157,4 +157,4 @@ When you need finer control, each topic has its own page: Curious how it works underneath? See [Under the hood](how-it-works.md). - + diff --git a/docs/guides/frontends/static-site/redirects.md b/docs/guides/frontends/static-site/redirects.md index dc9a86cf..9e9fbdf2 100644 --- a/docs/guides/frontends/static-site/redirects.md +++ b/docs/guides/frontends/static-site/redirects.md @@ -4,7 +4,7 @@ description: "The _redirects file: permanent and temporary redirects, rewrites, sidebar: order: 3 source_repo: "dfinity/certified-assets" -source_ref: "v0.4.0" +source_ref: "853c291" --- Add a file named `_redirects` to the root of your asset directory to send one path @@ -111,4 +111,4 @@ serve, and a verifying gateway would reject one anyway. (The same constraint is Static rules (exact paths, `/*` subtrees, and fixed destinations) cover the common cases and stay fully certifiable, so those are what `_redirects` supports. - + diff --git a/docs/guides/frontends/static-site/routing.md b/docs/guides/frontends/static-site/routing.md index f4794d7f..d23ddcb9 100644 --- a/docs/guides/frontends/static-site/routing.md +++ b/docs/guides/frontends/static-site/routing.md @@ -4,7 +4,7 @@ description: "How request paths resolve to files, clean URLs, trailing slashes, sidebar: order: 2 source_repo: "dfinity/certified-assets" -source_ref: "v0.4.0" +source_ref: "853c291" --- This page explains how an incoming request path resolves to one of your files: the @@ -131,4 +131,4 @@ for a complete, runnable project. file's contents at a different URL. - [Custom headers](headers.md): attach cache-control, CSP, and other headers to paths. - + diff --git a/docs/guides/frontends/static-site/site-files.md b/docs/guides/frontends/static-site/site-files.md index 112ad253..0457185c 100644 --- a/docs/guides/frontends/static-site/site-files.md +++ b/docs/guides/frontends/static-site/site-files.md @@ -4,7 +4,7 @@ description: "What gets uploaded, the special _redirects and _headers files, ski sidebar: order: 5 source_repo: "dfinity/certified-assets" -source_ref: "v0.4.0" +source_ref: "853c291" --- This page covers what actually gets uploaded from your asset directory, the special @@ -68,4 +68,4 @@ A file named `404.html` at the root of your directory becomes your site-wide not-found page. If you don't provide one, a certified default is served instead. See [not-found handling](routing.md#not-found-handling). - + diff --git a/docs/guides/frontends/static-site/verifying-contents.md b/docs/guides/frontends/static-site/verifying-contents.md index cef1ef17..7790abc2 100644 --- a/docs/guides/frontends/static-site/verifying-contents.md +++ b/docs/guides/frontends/static-site/verifying-contents.md @@ -4,7 +4,7 @@ description: "Prove a canister serves exactly a known build by reproducing its s sidebar: order: 7 source_repo: "dfinity/certified-assets" -source_ref: "v0.4.0" +source_ref: "853c291" --- Certification proves that what the canister **serves** matches what it has @@ -192,4 +192,4 @@ visitor's browser. The last link in that chain is the visitor's gateway: over a so the state hash still says what the canister committed to but no longer guarantees that a visitor received it. - +