WEB-105
Site support center (bug report + screenshots, contact, ban review, recovery), cookie-less analytics + web vitals, sitemap/robots/manifest, leak scan
Evidence
From logs/evidence/WEB-105/. Click a thumbnail for the full image.
Images (53)





















































Clips (8)
Tests
$ cd apps/site && ZOEN_DEV_PAGES=1 pnpm build >/dev/null 2>&1 && node scripts/leakscan.mjs && ZOEN_DEV_PAGES=1 ZOEN_EVIDENCE_TASK=WEB-105 pnpm exec playwright test --workers=1 --reporter=line$ cd apps/site && ZOEN_DEV_PAGES=1 pnpm build >/dev/null 2>&1 && node scripts/leakscan.mjs && ZOEN_DEV_PAGES=1 ZOEN_EVIDENCE_TASK=WEB-105 pnpm exec playwright test --workers=1 --reporter=line$ cd apps/site && ZOEN_DEV_PAGES=1 pnpm build >/dev/null 2>&1 && node scripts/leakscan.mjs && ZOEN_DEV_PAGES=1 ZOEN_EVIDENCE_TASK=WEB-105 pnpm exec playwright test --workers=1 --reporter=line$ cd apps/site && ZOEN_DEV_PAGES=1 pnpm build >/dev/null 2>&1 && node scripts/leakscan.mjs && ZOEN_DEV_PAGES=1 ZOEN_EVIDENCE_TASK=WEB-105 pnpm exec playwright test --workers=1 --reporter=lineNotes
2026-10-04 20:47 UTC · Support center: bug report (up to 3 screenshots, decoded + re-encoded to WebP server-side → no EXIF/location; verified), ban review (ban id required), account recovery, player report, contact — all with refs, honeypot + min fill time, DB rate limits. Analytics: first-party, cookie-less beacon → daily-changing server-side visitor hash; DNT/GPC respected (verified: no rows with DNT); Web Vitals reported. sitemap.xml (pages, 18 builds, posts), robots.txt, manifest. LEAK FOUND + FIXED: the image manifest bundled into client JS carried internal source paths with art-request ids → sources moved to lib/media.sources.json (never imported by the app); scripts/leakscan.mjs now gates built HTML/RSC/JS (8 canaries + every server secret value). UX FIX: React's automatic form reset wiped typed fields after validation errors → useFormAction keeps values (no-JS submit still works).
