editing
Content guide
Where hero copy, features, docs, and desk notes are edited.
Authored product copy is TypeScript, so a change is reviewable.
| File | What it feeds |
|---|---|
| src/content/site.ts | Name, warning, store link, listing facts, contract facts, the store/release/status-doc tracks and the unverified block, nav |
| src/content/features.ts | Feature groups and status badges |
| src/content/routes.ts | The 14-route table |
| src/content/security.ts | Principles, gaps, signing notes |
| src/content/architecture.ts | Five-layer flow and contract breaks |
| src/content/ai.ts | MCP policy tables |
| src/content/roadmap.ts | Numbered open and blocked steps |
| src/content/changelog.ts | Authored release history |
| src/content/docs.ts | Docs hub markdown |
| src/content/smoke.ts | Smoke checklist seed and open doc slots |
Desk
/desk writes Postgres: field notes and smoke-check marks. The gate requires an explicit DESK_PASSWORD; there is no default password. Without both DATABASE_URL and DESK_PASSWORD, the desk remains read-only. The gate does not protect a wallet. It only slows casual edits to the ledger.
Do not put secrets in a desk note. Notes are rendered publicly on the changelog.
Store link
The canonical install URL is exported as chromeStoreUrl from src/content/site.ts. Header, homepage, install page, footer, JSON-LD, llms files, and /api/catalog all read that constant. If the listing moves, change it once.
Release tracks
site.ts exports five things that must not be edited as if they were one:
site.listing— only ever what the live Chrome Web Store page says. Re-read the page before touching it and record the date inverifiedOn. A submission, a merge, and a GitHub release are all forbidden from writing here; on 2026-10-04 a changed public page did.storeStatus— the package in front of the store and the date it was published.staterunsupload-pending→in-review→published, and reachingpublishedis the only thing that licenses an edit tosite.listing.site.contract— the code facts on the extension'smainbranch, withauditedCommitandauditedOndeliberately lagging while the status document does.release— the merged, tagged source release, with its PR number, merge commit, and tag.auditedDocandunverified— what the repository still claims about itself, and what nobody has checked. Both exist so that "shipped" is never allowed to read as "verified".
releaseTracks renders the first three on the status page and the homepage. When two of them converge — as the store and the source did on 2026-10-04 — say so explicitly rather than deleting a track; the convergence is the news.