diff --git a/js/newsletter-config.js b/js/newsletter-config.js deleted file mode 100644 index 66f77f2..0000000 --- a/js/newsletter-config.js +++ /dev/null @@ -1,44 +0,0 @@ -/** - * Newsletter signup configuration. - * - * Only the non-secret serverless endpoint URL lives here. The serverless - * function authenticates with an API token it reads from platform env/secrets - * at deploy time — never from this module and never from any client-served - * asset. Do NOT add a token or any other secret to this file: the client must - * never carry a credential, and anything committed here is public. - */ - -/** True when the value is an absolute URL whose protocol is https:. */ -export function isHttpsUrl(value) { - try { - return new URL(String(value)).protocol === "https:"; - } catch { - return false; - } -} - -/** - * Enforce the https-only rule on a configured endpoint, mirroring the protocol - * allowlist pattern in js/reading-list.js (tightened to https). Throws when the - * endpoint would silently downgrade submissions to plaintext. - * - * @param {string} endpoint - * @returns {true} - */ -export function validateEndpoint(endpoint) { - if (!isHttpsUrl(endpoint)) { - throw new Error("NEWSLETTER_ENDPOINT must be an https:// URL"); - } - return true; -} - -/** - * The serverless endpoint the signup form POSTs to. - * - * https-only is asserted here at config load time (and covered by tests), so a - * deployer pointing this at an http:// URL fails fast instead of shipping a - * downgraded endpoint. - */ -export const NEWSLETTER_ENDPOINT = "https://example.com/api/newsletter-subscribers"; - -validateEndpoint(NEWSLETTER_ENDPOINT);