· Combined website release
Green redesign and AI-readable public content
The owner approved publishing the green redesign and public-readability improvements together. The earlier local-only notes below describe preparation milestones; this entry records the combined release checks and supersedes their open preview issues.
The production preview now runs the actual hosting build using Cloudflare’s local runtime. Its local settings are resolved from the project folder, without copying credentials into the build or enabling remote resource bindings. All existing declared application-package versions are retained; a pinned development-only preview tool was added.
The earlier security warning was reviewed and addressed with the framework’s same-origin protection for server-function requests. Normal website requests pass; cross-site and unverified action requests are rejected. Public HTML, the sitemap, the content index, and the separately authenticated training-agent API are outside this origin check. Existing sign-in, database permissions, and private storage protections remain in place.
Release verification: all 232 tests pass, including 15 public-content checks against the production build without JavaScript and 11 origin-protection tests. Read-only production-preview checks also confirm same-origin public-data requests succeed and anonymous requests for private Sorta records are rejected without exposing image URLs. The build, TypeScript check, and targeted code checks pass. No image records, annotations, review decisions, datasets, or training runs were changed by this release.
Published to ftggcig.com on 6 September 2026 through the existing GitHub and Lovable connection, without Lovable chat prompts. All 15 live public-content checks pass: ten readable public pages, the sitemap and plain-text content index, protected-page indexing rules, and a real missing-page response. The live stylesheet contains the approved green accent, and MyMoney Journey includes actual milestone content in its initial HTML. Live read-only checks also confirm the origin protection and rejection of anonymous requests for private images. No browser visual or authenticated editor testing was performed during this release.
One separate web-reading service still rejected the domain with a retrieval safety error while direct public HTTP checks passed. The cause remains unconfirmed; this is not evidence that every AI provider can retrieve the site or that a site firewall caused the failure. No security protection was disabled. Search indexing and citations remain controlled by each service, not guaranteed by these changes.