/** * Newsletter signup configuration. * * Only the non-secret serverless endpoint URL lives here. The serverless * function authenticates with an API token it reads from platform env/secrets * at deploy time — never from this module and never from any client-served * asset. Do NOT add a token or any other secret to this file: the client must * never carry a credential, and anything committed here is public. */ /** True when the value is an absolute URL whose protocol is https:. */ export function isHttpsUrl(value) { try { return new URL(String(value)).protocol === "https:"; } catch { return false; } } /** * Enforce the https-only rule on a configured endpoint, mirroring the protocol * allowlist pattern in js/reading-list.js (tightened to https). Throws when the * endpoint would silently downgrade submissions to plaintext. * * @param {string} endpoint * @returns {true} */ export function validateEndpoint(endpoint) { if (!isHttpsUrl(endpoint)) { throw new Error("NEWSLETTER_ENDPOINT must be an https:// URL"); } return true; } /** * The serverless endpoint the signup form POSTs to. * * https-only is asserted here at config load time (and covered by tests), so a * deployer pointing this at an http:// URL fails fast instead of shipping a * downgraded endpoint. */ export const NEWSLETTER_ENDPOINT = "https://example.com/api/newsletter-subscribers"; validateEndpoint(NEWSLETTER_ENDPOINT);