999c4b65ef
Implements the M3-frontend slice of the §22 multi-project track, per docs/superpowers/specs/2026-06-03-m3-frontend-design.md (design merged in #10). Completes the runtime-config cut 0.33.0 (M3-backend Plan A) began. Frontend: - DeploymentProvider boots GET /api/deployment → {name, tagline, defaultProjectId, projects}; brandTitle() neutral 'RFC' pre-fetch fallback. - /p/:projectId/* routing with generic /e/<slug> segment. ProjectLayout fetches /api/projects/:id, applies per-project theme (reset on switch), provides ProjectContext, guards the corpus (served only for the default; others get NotServedPlaceholder — decouples this slice from Plan B). - Directory at / (2+ projects) with N=1 redirect into the single project; ProjectSwitcher in deployment chrome; entry-noun by project type. - VITE_APP_NAME hard cut: removed from vite.config + index.html; the 6 brand reads now use deployment.name via context; static <title>RFC</title> + JS document.title. Internal /rfc·/proposals links → /p/<project>/e|proposals via lib/entryPaths. Backend: - GET /api/deployment returns default_project_id (the guard contract). - Server-side 308s: /rfc/<slug>, /rfc/<slug>/pr/<n>, /proposals/<n> → /p/<default>/… . nginx (testing + prod) routes /rfc/ and /proposals/ to the backend. Tests: 3 new backend redirect/deployment tests (438 pass); Vitest unit for DeploymentProvider, ProjectLayout (theme/guard/404), Directory (11 pass); clean build with no VITE_APP_NAME. Playwright e2e deferred until Tier-1 seeds a registry (see CHANGELOG 0.35.0 step 5). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
122 lines
4.7 KiB
React
122 lines
4.7 KiB
React
// Privacy.jsx — v0.13.0 / roadmap item #11 / SPEC §14.5.
|
|
//
|
|
// The framework's default privacy policy page. Reachable by anonymous
|
|
// and authenticated viewers alike at `/privacy`. The text below is a
|
|
// minimal stub that describes the framework's stance; deployments are
|
|
// expected to override it via the `VITE_PRIVACY_POLICY_URL` env var.
|
|
//
|
|
// When `VITE_PRIVACY_POLICY_URL` is set:
|
|
// - http(s) URL → the page renders the framework's stub above a
|
|
// "Read the full deployment policy" link to the configured URL.
|
|
// We don't iframe-embed third-party policy hosts because their
|
|
// Content-Security-Policy frequently refuses framing; the link is
|
|
// the predictable affordance.
|
|
//
|
|
// The framework's stub is intentionally short — the rules that matter
|
|
// to a user are: (1) what categories of cookies the app sets, (2) how
|
|
// to change consent, (3) where to reach the deployment operator with a
|
|
// complaint. Each deployment's content repo can carry a fuller version.
|
|
|
|
import { useNavigate, Link } from 'react-router-dom'
|
|
import { useDeployment } from '../context/DeploymentProvider'
|
|
|
|
export default function Privacy() {
|
|
const navigate = useNavigate()
|
|
const deploymentUrl = (import.meta.env.VITE_PRIVACY_POLICY_URL || '').trim()
|
|
// §22.9: deployment name from runtime config (was VITE_APP_NAME).
|
|
const { name } = useDeployment()
|
|
const appName = name || 'this deployment'
|
|
|
|
return (
|
|
<div className="policy-page">
|
|
<header className="policy-header">
|
|
<button
|
|
className="policy-back"
|
|
onClick={() => (history.length > 1 ? navigate(-1) : navigate('/'))}
|
|
>
|
|
← Back
|
|
</button>
|
|
<span className="policy-title">Privacy policy</span>
|
|
</header>
|
|
<article className="policy-body">
|
|
<h1>Privacy policy</h1>
|
|
<p className="policy-subtitle">
|
|
What {appName} stores, why, and how to control it.
|
|
</p>
|
|
|
|
<h2>What we store</h2>
|
|
<p>
|
|
{appName} runs on the Wiggleverse RFC framework. The framework
|
|
stores the identity you sign in with (your Gitea login,
|
|
display name, email, and avatar URL), the proposals and edits
|
|
you author, the discussion threads you participate in, and
|
|
your notification preferences. Authoring is public by design —
|
|
this is a framework for public-async RFC work, and threads,
|
|
changes, and PRs are visible to anyone who reaches the
|
|
deployment. Settings (notification toggles, quiet hours, mute
|
|
list, cookie consent) are private to your account.
|
|
</p>
|
|
|
|
<h2>Cookies</h2>
|
|
<p>
|
|
The app sets a small set of cookies. The full list is on the{' '}
|
|
<Link to="/cookies">cookies policy page</Link>. You can choose
|
|
which categories you allow from the consent banner shown on
|
|
your first visit or from <Link to="/settings/notifications">
|
|
Settings → Privacy & cookies</Link> any time
|
|
afterwards.
|
|
</p>
|
|
|
|
<h2>Analytics</h2>
|
|
<p>
|
|
The framework supports an optional anonymous analytics layer
|
|
gated behind your consent choice. As of v0.13.0 no analytics
|
|
SDK ships in the framework; deployments that enable analytics
|
|
do so via a later framework version (roadmap item #13). The
|
|
consent toggle exists today so the gate is already in place
|
|
when the SDK lands.
|
|
</p>
|
|
|
|
<h2>Your data, your control</h2>
|
|
<ul>
|
|
<li>Revoke cookie consent any time from settings.</li>
|
|
<li>
|
|
Edit notification preferences — including the global email
|
|
opt-out — from{' '}
|
|
<Link to="/settings/notifications">notification settings</Link>.
|
|
</li>
|
|
<li>
|
|
Your authored content (proposals, threads, edits) is public
|
|
and not retractable from the meta-repo's Git history. If you
|
|
need a redaction, reach the deployment operator directly.
|
|
</li>
|
|
</ul>
|
|
|
|
{deploymentUrl ? (
|
|
<>
|
|
<h2>Deployment-specific policy</h2>
|
|
<p>
|
|
This deployment may layer additional policy on top of the
|
|
framework's defaults. Read the full deployment policy at:
|
|
</p>
|
|
<p>
|
|
<a href={deploymentUrl} target="_blank" rel="noopener noreferrer">
|
|
{deploymentUrl}
|
|
</a>
|
|
</p>
|
|
</>
|
|
) : (
|
|
<>
|
|
<h2>Deployment contact</h2>
|
|
<p>
|
|
For deployment-specific privacy questions — data subject
|
|
requests, redaction requests, complaints — contact the
|
|
operator of {appName}.
|
|
</p>
|
|
</>
|
|
)}
|
|
</article>
|
|
</div>
|
|
)
|
|
}
|