apps/marketing — Jekyll Static Site
apps/marketing — Jekyll Static Site
Runs on Vercel (framework=jekyll), fronted by Cloudflare. Public content only.
Rules
- No secrets, no
service_role, no privileged auth logic. This is a fully public, statically-generated site. The only “auth” awareness allowed is reading a non-sensitive.webglo.orgcookie to relabel nav (do NOT call a portal API on every page view). - Headers/CSP live in
apps/marketing/vercel.json, NOT in_headers(that file is a dead Cloudflare Pages artifact — editing it does nothing on prod). - Build artifacts:
assets/css/main.cssandassets/js/site.min.jsare generated bynpm run build:css/build:js(Vercel runs these on deploy). Editassets/js/site.js, neversite.min.js(it’s gitignored and regenerated). - Performance budget (see
docs/reviews/2026-07-01-codebase-review.md): no runtime 3D libs for decoration; lazy-load video/heavy media; optimized/sized images; honorprefers-reduced-motion. - Inline
<script>is discouraged — the CSP still allowsunsafe-inline, but the goal is to remove it (security F11), so don’t add new inline scripts.
Boundaries
- May NOT import from
apps/portal/**orworkers/**. Cross-app links are URLs, not imports.
Content
- Data in
_data/*.yml, includes in_includes/, layouts in_layouts/. Blog in_posts/. - Legal pages: the
.mdfile is the live content (/policy/); the small.htmltwin is a legacy-URL redirect stub (/policy.html→/policy/) — keep both.
WebGlo