Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .sources/upstream.json
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@
"synced": [
{
"repo": "dfinity/certified-assets",
"pinned": "v0.4.0",
"pinned": "853c291",
"source": "docs/",
"target": "docs/guides/frontends/static-site/",
"script": "scripts/sync-static-site.mjs",
Expand Down
4 changes: 2 additions & 2 deletions docs/guides/frontends/static-site/access-protection.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: "Put a login page in front of a private or preview site with revoca
sidebar:
order: 6
source_repo: "dfinity/certified-assets"
source_ref: "v0.4.0"
source_ref: "853c291"
---

By default every deployed app is public. **Access protection** puts a login screen
Expand Down Expand Up @@ -197,4 +197,4 @@ makes), unauthorized visitors can't pull your content. But:
Use it to keep a preview or in-progress app out of public view, not to protect
secrets from a determined adversary.

<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/access-protection.md at v0.4.0. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/access-protection.md at 853c291. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
4 changes: 2 additions & 2 deletions docs/guides/frontends/static-site/headers.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: "The _headers file: cache-control, security headers, content types,
sidebar:
order: 4
source_repo: "dfinity/certified-assets"
source_ref: "v0.4.0"
source_ref: "853c291"
---

Add a file named `_headers` to the root of your asset directory to attach response
Expand Down Expand Up @@ -137,4 +137,4 @@ immediately.
This list is intentionally conservative and may be relaxed in future releases; it's
easier to allow a header later than to start rejecting one that sites already rely on.

<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/headers.md at v0.4.0. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/headers.md at 853c291. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
11 changes: 6 additions & 5 deletions docs/guides/frontends/static-site/how-it-works.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: "How the canister certifies responses, serves large assets, negotia
sidebar:
order: 8
source_repo: "dfinity/certified-assets"
source_ref: "v0.4.0"
source_ref: "853c291"
---

You don't need any of this to use certified-assets; the [overview](overview.md) is
Expand Down Expand Up @@ -67,9 +67,10 @@ outlived the problem they solved, and survive mainly as a debugging aid.

This canister never needed the escape hatch. It is v2-only and certifies everything, so
it behaves identically on both hostnames: it attaches the certificate either way, and on
`raw` the gateway simply discards it. Nothing about the canister's guarantee weakens
there, but the client has chosen a party that doesn't check, so it gets no better
assurance than from an ordinary web host.
`raw` the gateway forwards it without checking it. Nothing about the canister's guarantee
weakens there, but the client has chosen a party that doesn't check, so unless it
verifies the certificate itself, it gets no better assurance than from an ordinary web
host.

**The canister can't reliably refuse `raw` requests.** Its only clue is the `Host`
header, which the client supplies and nothing authenticates. Matching it against `raw`
Expand Down Expand Up @@ -170,4 +171,4 @@ in-place upgrade that keeps all state, while a **breaking** release reinstalls a
fresh sync re-uploads everything. See
[Releasing](https://github.com/dfinity/certified-assets/blob/main/README.md#releasing) for the details.

<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/how-it-works.md at v0.4.0. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/how-it-works.md at 853c291. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
4 changes: 2 additions & 2 deletions docs/guides/frontends/static-site/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: "Deploy a built frontend, docs, or any folder of files to a caniste
sidebar:
order: 1
source_repo: "dfinity/certified-assets"
source_ref: "v0.4.0"
source_ref: "853c291"
---

Deploy a **static site** (a built frontend, docs, or any folder of files) to a
Expand Down Expand Up @@ -157,4 +157,4 @@ When you need finer control, each topic has its own page:

Curious how it works underneath? See [Under the hood](how-it-works.md).

<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/overview.md at v0.4.0. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/overview.md at 853c291. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
4 changes: 2 additions & 2 deletions docs/guides/frontends/static-site/redirects.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: "The _redirects file: permanent and temporary redirects, rewrites,
sidebar:
order: 3
source_repo: "dfinity/certified-assets"
source_ref: "v0.4.0"
source_ref: "853c291"
---

Add a file named `_redirects` to the root of your asset directory to send one path
Expand Down Expand Up @@ -111,4 +111,4 @@ serve, and a verifying gateway would reject one anyway. (The same constraint is
Static rules (exact paths, `/*` subtrees, and fixed destinations) cover the common
cases and stay fully certifiable, so those are what `_redirects` supports.

<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/redirects.md at v0.4.0. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/redirects.md at 853c291. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
4 changes: 2 additions & 2 deletions docs/guides/frontends/static-site/routing.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: "How request paths resolve to files, clean URLs, trailing slashes,
sidebar:
order: 2
source_repo: "dfinity/certified-assets"
source_ref: "v0.4.0"
source_ref: "853c291"
---

This page explains how an incoming request path resolves to one of your files: the
Expand Down Expand Up @@ -131,4 +131,4 @@ for a complete, runnable project.
file's contents at a different URL.
- [Custom headers](headers.md): attach cache-control, CSP, and other headers to paths.

<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/routing.md at v0.4.0. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/routing.md at 853c291. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
4 changes: 2 additions & 2 deletions docs/guides/frontends/static-site/site-files.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: "What gets uploaded, the special _redirects and _headers files, ski
sidebar:
order: 5
source_repo: "dfinity/certified-assets"
source_ref: "v0.4.0"
source_ref: "853c291"
---

This page covers what actually gets uploaded from your asset directory, the special
Expand Down Expand Up @@ -68,4 +68,4 @@ A file named `404.html` at the root of your directory becomes your site-wide
not-found page. If you don't provide one, a certified default is served instead. See
[not-found handling](routing.md#not-found-handling).

<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/site-files.md at v0.4.0. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/site-files.md at 853c291. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
4 changes: 2 additions & 2 deletions docs/guides/frontends/static-site/verifying-contents.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: "Prove a canister serves exactly a known build by reproducing its s
sidebar:
order: 7
source_repo: "dfinity/certified-assets"
source_ref: "v0.4.0"
source_ref: "853c291"
---

Certification proves that what the canister **serves** matches what it has
Expand Down Expand Up @@ -192,4 +192,4 @@ visitor's browser. The last link in that chain is the visitor's gateway: over a
so the state hash still says what the canister committed to but no longer guarantees
that a visitor received it.

<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/verifying-contents.md at v0.4.0. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
<!-- Generated by scripts/sync-static-site.mjs from dfinity/certified-assets docs/verifying-contents.md at 853c291. Do not edit directly: the next sync overwrites it. Content changes belong upstream. -->
Loading