NAMESPACE_MAP.yaml
# Route namespace map — the banned-route gate (Run 1 item 1.B.1, 2026-09-02).
#
# Every served package declares the URL prefixes it may own. tests/routes/
# test_namespace_map.py enumerates the LIVE route table at test time (Flask
# `app.url_map`; never a hand-maintained tuple — rule 01 "scope is derived from
# the live route table") and fails on any rule outside its package's prefixes,
# naming the file that registered it. Adding a route therefore means adding
# its prefix here in the same change, with the ruling that ratified it.
#
# Matching: a rule matches a prefix when it equals the prefix, or the prefix
# ends with "/" and the rule starts with it. Prefix "/" alone matches only the
# root rule, so the catch-all `/<path:filename>` needs its own explicit entry.
version: 1
packages:
- name: mizoki-website
app: "# MIZ OKI 3.5/app.py"
framework: flask
# Loader for the test: dotted "module:factory" resolved with the package
# directory on sys.path. The factory takes an optional runtime.
factory: "app:create_app"
allowed_prefixes:
# --- public pages (canon-locked marketing surface) ---
- "/"
- "/index.html"
- "/signal"
# owner front door r1.3, P0 (2026-10-04): /signals answered 404 in the
# 4 Oct live audit; it 301s to /signal and serves nothing of its own.
- "/signals"
# owner front door r1.3, P1 (2026-10-04): /platform answered 404 in the
# 4 Oct live audit; it 301s to the tech host and serves nothing of its own.
- "/platform"
- "/signal/"
- "/signal.html"
- "/signal-thresholds.html"
- "/signal-budget.html"
- "/signal-creative.html"
- "/signal-audiences.html"
- "/signal-measurement.html"
- "/shopify"
- "/shopify.html"
- "/marketing"
- "/marketing/"
- "/media"
# Executive Demo (r1.0 2026-09-12; placed under /media r1.1, owner ruling
# 2026-09-13; slug renamed 2026-09-14): /media/demo, with /media/executive-demo
# as a 308 into it — both covered by the /media/ prefix below.
# robots noindex, deliberately not sitemapped; no root-level filename route.
- "/media/"
- "/media-buying"
- "/media-buying.html"
- "/demo"
- "/demo/"
- "/demo.html"
- "/demo-signal.html"
- "/demo-counsel.html"
- "/demo-estate.html"
- "/demo-capital.html"
- "/demo-risk.html"
- "/demo-nexus.html"
- "/demo-opener.html"
- "/counsel"
- "/counsel.html"
- "/estate"
- "/estate.html"
- "/capital"
- "/capital.html"
- "/risk"
- "/risk.html"
- "/privacy"
- "/privacy.html"
- "/terms"
- "/terms.html"
- "/pricing"
- "/pricing.html"
- "/mizuki3"
- "/mizuki3.html"
- "/walkthrough"
- "/walkthrough.html"
- "/contact"
- "/contact.html"
# --- Ecosystem animation standalone player & voice-over audio (PRs #938, #940) ---
- "/animation"
- "/animation/"
- "/animation.html"
- "/ecosystem-animation"
- "/intelligence"
- "/vision"
- "/intent"
- "/intent/"
- "/executive-briefing/"
- "/docs"
- "/docs/"
- "/blog"
- "/blog/"
- "/blogs"
- "/blogs.html"
- "/blogs/"
- "/rss.xml"
- "/11/"
- "/console"
- "/console/"
- "/infrastructure/"
- "/templates/"
- "/schemas/"
# legacy pages that 301 to "/" (content_qa rule F derives the dead-end set from these)
- "/how-it-works.html"
- "/platform.html"
- "/security.html"
- "/industries.html"
- "/case-studies.html"
- "/resources.html"
- "/roi.html"
- "/investor.html"
- "/sales-one-pager.html"
# --- well-known / static ---
- "/favicon.ico"
- "/apple-touch-icon.png"
- "/apple-touch-icon-precomposed.png"
- "/robots.txt"
- "/sitemap.xml"
- "/assets/"
# owner front door r1.3, P3 (2026-10-04): the ecosystem bar for properties
# that cannot include its static partial; one fixed file, nothing else
# under /shared/ is served.
- "/shared/ecosystem-bar.js"
- "/<path:filename>" # top-level static catch-all (app.py top_level_static)
# --- auth / admin ---
- "/login"
- "/login.html"
- "/logout"
- "/dashboard"
- "/admin"
- "/admin/"
- "/health"
# --- tracked CTA redirect + A/B/C outcome instrumentation ---
# RATIFIED as built: owner-issued SITE A/B/C TEST — DESIGN FIX r1.0
# (docs/reports/SITE_ABC_TEST_IMPLEMENTATION_2026-08-22.md), pre-registered
# (# MIZ OKI 3.5/docs/marketing/abtest-preregistration-signal-landing.md),
# owner-deployed and live-probed dark 2026-08-26 (LAUNCH_REGISTER L-08:
# GET /api/abtest/state -> mode:"off"). There is NO bare /api/abtest route.
- "/go/"
- "/api/abtest/"
# --- API namespaces ---
- "/api/health"
- "/api/mcp/"
- "/api/boss/"
- "/api/demo/"
- "/api/briefing/"
- "/api/admin/"
# --- Run 1 item 1.F: measurement without egress (flag-gated, default OFF) ---
- "/event"
- "/shopify/event"
- "/shopify/pilot-request"
# --- Lane 5 S4 (2026-09-02): AEO/GEO authority pages + llms.txt, flag LEARN_PAGES default OFF -> 404; HELD (OPEN_ITEMS S4-1) ---
- "/learn"
- "/learn/"
- "/llms.txt"
# Service-local route tables (Cloud Run services, NOT the site). Listed so a
# served route outside its package has one place to be looked up; the Flask
# route-table test above reads only `packages`.
services:
- name: mcp-server
source: services/mcp_server
routes: ["/health", "/readyz", "/mcp", "/.well-known/ucp"] # POST /mcp = JSON-RPC 2.0 (initialize | ping | tools/list | tools/call); GET /.well-known/ucp = UCP-SHAPED read-only profile (owner ruling S3-5 (a), 2026-09-15; same bearer, tenant from token)
posture: "flag-OFF -> 503 not_configured on every route but /health; not deployed (Wave 3 S3, 2026-09-02; S3-5 route 2026-09-15). tests/mcp/test_ucp_profile.py pins routes == the live table"
- name: service-canonical-ingestion
source: services/service-canonical-ingestion
routes: ["/api/v1/origin/agent-share:evaluate"] # POST; verify_caller; AGENT_SHARE_THRESHOLD publish path (audit chain)
posture: "flag ORIGIN_CLASSIFIER OFF -> 503 not_configured (Wave 3 S2, 2026-09-02); other routes of this service predate the map"