NAMESPACE_MAP.yaml

# Route namespace map — the banned-route gate (Run 1 item 1.B.1, 2026-09-02).
#
# Every served package declares the URL prefixes it may own. tests/routes/
# test_namespace_map.py enumerates the LIVE route table at test time (Flask
# `app.url_map`; never a hand-maintained tuple — rule 01 "scope is derived from
# the live route table") and fails on any rule outside its package's prefixes,
# naming the file that registered it. Adding a route therefore means adding
# its prefix here in the same change, with the ruling that ratified it.
#
# Matching: a rule matches a prefix when it equals the prefix, or the prefix
# ends with "/" and the rule starts with it. Prefix "/" alone matches only the
# root rule, so the catch-all `/<path:filename>` needs its own explicit entry.
version: 1
packages:
  - name: mizoki-website
    app: "# MIZ OKI 3.5/app.py"
    framework: flask
    # Loader for the test: dotted "module:factory" resolved with the package
    # directory on sys.path. The factory takes an optional runtime.
    factory: "app:create_app"
    allowed_prefixes:
      # --- public pages (canon-locked marketing surface) ---
      - "/"
      - "/index.html"
      - "/signal"
      # owner front door r1.3, P0 (2026-10-04): /signals answered 404 in the
      # 4 Oct live audit; it 301s to /signal and serves nothing of its own.
      - "/signals"
      # owner front door r1.3, P1 (2026-10-04): /platform answered 404 in the
      # 4 Oct live audit; it 301s to the tech host and serves nothing of its own.
      - "/platform"
      - "/signal/"
      - "/signal.html"
      - "/signal-thresholds.html"
      - "/signal-budget.html"
      - "/signal-creative.html"
      - "/signal-audiences.html"
      - "/signal-measurement.html"
      - "/shopify"
      - "/shopify.html"
      - "/marketing"
      - "/marketing/"
      - "/media"
      # Executive Demo (r1.0 2026-09-12; placed under /media r1.1, owner ruling
      # 2026-09-13; slug renamed 2026-09-14): /media/demo, with /media/executive-demo
      # as a 308 into it — both covered by the /media/ prefix below.
      # robots noindex, deliberately not sitemapped; no root-level filename route.
      - "/media/"
      - "/media-buying"
      - "/media-buying.html"
      - "/demo"
      - "/demo/"
      - "/demo.html"
      - "/demo-signal.html"
      - "/demo-counsel.html"
      - "/demo-estate.html"
      - "/demo-capital.html"
      - "/demo-risk.html"
      - "/demo-nexus.html"
      - "/demo-opener.html"
      - "/counsel"
      - "/counsel.html"
      - "/estate"
      - "/estate.html"
      - "/capital"
      - "/capital.html"
      - "/risk"
      - "/risk.html"
      - "/privacy"
      - "/privacy.html"
      - "/terms"
      - "/terms.html"
      - "/pricing"
      - "/pricing.html"
      - "/mizuki3"
      - "/mizuki3.html"
      - "/walkthrough"
      - "/walkthrough.html"
      - "/contact"
      - "/contact.html"
      # --- Ecosystem animation standalone player & voice-over audio (PRs #938, #940) ---
      - "/animation"
      - "/animation/"
      - "/animation.html"
      - "/ecosystem-animation"
      - "/intelligence"
      - "/vision"
      - "/intent"
      - "/intent/"
      - "/executive-briefing/"
      - "/docs"
      - "/docs/"
      - "/blog"
      - "/blog/"
      - "/blogs"
      - "/blogs.html"
      - "/blogs/"
      - "/rss.xml"
      - "/11/"
      - "/console"
      - "/console/"
      - "/infrastructure/"
      - "/templates/"
      - "/schemas/"
      # legacy pages that 301 to "/" (content_qa rule F derives the dead-end set from these)
      - "/how-it-works.html"
      - "/platform.html"
      - "/security.html"
      - "/industries.html"
      - "/case-studies.html"
      - "/resources.html"
      - "/roi.html"
      - "/investor.html"
      - "/sales-one-pager.html"
      # --- well-known / static ---
      - "/favicon.ico"
      - "/apple-touch-icon.png"
      - "/apple-touch-icon-precomposed.png"
      - "/robots.txt"
      - "/sitemap.xml"
      - "/assets/"
      # owner front door r1.3, P3 (2026-10-04): the ecosystem bar for properties
      # that cannot include its static partial; one fixed file, nothing else
      # under /shared/ is served.
      - "/shared/ecosystem-bar.js"
      - "/<path:filename>"          # top-level static catch-all (app.py top_level_static)
      # --- auth / admin ---
      - "/login"
      - "/login.html"
      - "/logout"
      - "/dashboard"
      - "/admin"
      - "/admin/"
      - "/health"
      # --- tracked CTA redirect + A/B/C outcome instrumentation ---
      # RATIFIED as built: owner-issued SITE A/B/C TEST — DESIGN FIX r1.0
      # (docs/reports/SITE_ABC_TEST_IMPLEMENTATION_2026-08-22.md), pre-registered
      # (# MIZ OKI 3.5/docs/marketing/abtest-preregistration-signal-landing.md),
      # owner-deployed and live-probed dark 2026-08-26 (LAUNCH_REGISTER L-08:
      # GET /api/abtest/state -> mode:"off"). There is NO bare /api/abtest route.
      - "/go/"
      - "/api/abtest/"
      # --- API namespaces ---
      - "/api/health"
      - "/api/mcp/"
      - "/api/boss/"
      - "/api/demo/"
      - "/api/briefing/"
      - "/api/admin/"
      # --- Run 1 item 1.F: measurement without egress (flag-gated, default OFF) ---
      - "/event"
      - "/shopify/event"
      - "/shopify/pilot-request"
      # --- Lane 5 S4 (2026-09-02): AEO/GEO authority pages + llms.txt, flag LEARN_PAGES default OFF -> 404; HELD (OPEN_ITEMS S4-1) ---
      - "/learn"
      - "/learn/"
      - "/llms.txt"

# Service-local route tables (Cloud Run services, NOT the site). Listed so a
# served route outside its package has one place to be looked up; the Flask
# route-table test above reads only `packages`.
services:
  - name: mcp-server
    source: services/mcp_server
    routes: ["/health", "/readyz", "/mcp", "/.well-known/ucp"]   # POST /mcp = JSON-RPC 2.0 (initialize | ping | tools/list | tools/call); GET /.well-known/ucp = UCP-SHAPED read-only profile (owner ruling S3-5 (a), 2026-09-15; same bearer, tenant from token)
    posture: "flag-OFF -> 503 not_configured on every route but /health; not deployed (Wave 3 S3, 2026-09-02; S3-5 route 2026-09-15). tests/mcp/test_ucp_profile.py pins routes == the live table"
  - name: service-canonical-ingestion
    source: services/service-canonical-ingestion
    routes: ["/api/v1/origin/agent-share:evaluate"]   # POST; verify_caller; AGENT_SHARE_THRESHOLD publish path (audit chain)
    posture: "flag ORIGIN_CLASSIFIER OFF -> 503 not_configured (Wave 3 S2, 2026-09-02); other routes of this service predate the map"
← All docsView source on GitHub →