From cb9cf703a870efd31871115a8fdd9f2411067c5d Mon Sep 17 00:00:00 2001 From: bot-implementer Date: Tue, 25 Aug 2026 19:15:56 +0000 Subject: [PATCH] docs: document the newsletter page and its config in the README --- README.md | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/README.md b/README.md index 97ce69b..0a1e729 100644 --- a/README.md +++ b/README.md @@ -10,6 +10,26 @@ vanilla JavaScript. rendered from `data/reading-list.js`) - `contact.html` — contact page (opens the visitor's mail client with the form fields pre-filled via a `mailto:` link) +- `newsletter.html` — newsletter signup page (posts the visitor's email to a + configured serverless endpoint; no self-hosted backend or subscriber list + management) + +## Newsletter signup + +The signup form on `newsletter.html` POSTs the visitor's email to a serverless +endpoint. Everything is configured in one file — `js/newsletter-config.js`: + +- `NEWSLETTER_ENDPOINT` — the serverless endpoint the form POSTs to. +- `NEWSLETTER_API_TOKEN` — the API token sent in the `Authorization` header. + +**Security:** a real API token must never be committed to the repository. The +committed default is an empty placeholder; the deployer sets the real token in +`js/newsletter-config.js` at deploy time, and only then. The page logic reads +the token from this config module and never hardcodes one. + +When the token is missing or the endpoint rejects it, the visitor sees a fixed, +user-safe error message — the token or endpoint internals are never surfaced. +After a successful signup a confirmation message is shown. ## Reading list @@ -56,8 +76,11 @@ npm test index.html Home page reading.html Reading list page contact.html Contact page +newsletter.html Newsletter signup page css/style.css Global + responsive styles data/reading-list.js Curated reading list data (edit to add links) +js/newsletter-config.js Newsletter endpoint + API token (edit at deploy time) +js/newsletter.js Newsletter signup wiring: POST + user-safe errors (tested) js/mailto.js Pure mailto: URL builder (unit tested) js/contact.js Contact form wiring (browser + tests) js/reading-list.js Reading list renderer: data file -> grouped HTML (tested)