Devlog

A public record of what moved.

This log stays practical: what shipped, what tightened, and what changed on the public surface without turning the site into a running diary.

A first visit now follows the device language when no site language is saved.

When the browser has no saved Ronova site-language choice, the public website now checks the browser and operating-system language list and opens the matching English, German, French, Japanese, or Traditional Chinese route.

  • A language selected from the site, or an explicitly opened localized route, is remembered and takes priority over later environment detection.
  • Unsupported languages stay on English, Simplified Chinese is not mislabeled as Traditional Chinese, and no additional identity or account state is created.

0XX institutional accounts gained an opt-in Honorary Board and courtesy email flow.

Eligible human Ronova ID members can prepare a private-by-default recognition profile and request one verified @triluna.org forwarding alias without creating another account or receiving administrative authority.

  • Every public field is separately controlled; unpublished members, destinations, internal notes, verification data, and provider metadata remain private.
  • Email activation remains pending until a reviewed production routing provider, dedicated encryption key, and domain mail configuration pass end-to-end verification.

Archon now manages ordinary-account prefixes and roles from one account dashboard.

Archon now starts with an exact `XXX XXXXX XXXXX` UID search. Ordinary universal Ronova ID accounts can keep multiple prefix-derived IDs valid at once, choose one primary ID, and manage independent role grants from the selected account dashboard.

  • Changing the primary prefix preserves the previous ID as an explicitly active alias to the same immutable account; every active ID resolves to that one account and never grants authority by itself.
  • Each dashboard combines assigned IDs, role grants, effective permissions, sessions, authenticator summaries, recent activity, and UID history without exposing email, credential material, session hashes, or audit metadata.
  • The exact 000 00000 00000 and 999 99999 99999 accounts never appear in Archon search or per-account dashboards, and remain unchangeable at the API, coordinator, executor, and database boundaries.

Omni Archon gained its first private Gekka reader.

Archon can now search a bounded, redacted view of Gekka governance-code metadata through a private Gekka-owned executor. Ronova signs the request, the coordinator adds an executor-specific assertion, and Gekka independently checks both the contract and audience before reading its own database.

  • Results contain only opaque code IDs, labels, state, allowed contexts, use limits, dates, and an opaque version; bearer values, hashes, fragments, grants, notes, actor identities, cookies, and credentials never cross the boundary.
  • Code creation, revocation, restoration, roles, releases, emergency controls, billing, and raw secrets remain disabled until their project-owned mutation, recovery, and approval contracts pass separate drills.

Travel Evaluation now keeps Ronova-ID-owned records on the server.

Travel Evaluation now stores evaluations as server records owned by a Ronova ID. Public archives fetch published records, while only the authenticated owner can create, update, or delete their own records.

  • Local drafts remain in the browser until their owner explicitly saves them; public archive fetches do not expose draft data.
  • During typed edits, the active input remains mounted, preserving focus while record changes are saved.

Ronova ID displays now resolve from one authority.

Account, Archon, and Travel workbench surfaces now fetch the current mutable Ronova ID from a credentialed no-store API on ronova.dev and accept it only when its immutable subject matches the relying session.

  • The display response contains only the immutable subject, current identity descriptor, display name, and sign-in URL; it exposes no role, permission, credential, session material, or legacy alias.
  • id.ronova.dev and archon.ronova.dev keep host-only sessions but resolve the displayed ID from ronova.dev, including after a browser back/forward cache restore.
  • Exact v1 values remain visibly labelled as Legacy Ronova IDs until the production v2 data cutover; no old prefix is rewritten into a fabricated current identity.
  • Ronova ID remains an identifier, never authorization. Protected-principal, role, permission, account-status, and strong-session checks remain server-side.

Travel Evaluation keeps edits in place and archives compact.

The Travel Evaluation notebook no longer rebuilds its active sheet when a field changes, so sequential entry keeps focus, scroll position, and browser-local draft state intact. Create, Flight archive, Lounge archive, and Hotel archive are now compact same-document windows instead of one long mixed page. Archive taxonomy uses restrained class and category accents, while result badges keep their own quality scale.

  • Text, metadata, and score commits update only the affected sheet; archive filtering redraws after a short typing pause rather than on every character.
  • The four windows are bookmarkable same-document views, so switching between a private draft and a category archive does not reload or discard the mounted sheet.
  • Lounge, hotel, and flight taxonomy now carries a consistent accent through the archive and editor, while result labels use a separate accessible tonal scale.
  • The workbench remains browser-local behind the existing Ronova ID boundary; no second account system, remote data change, or deployment is implied by this refinement.

Universal motion published and verified.

This production release adds top- and bottom-directional motion where applicable, pressed feedback for controls, and reduced-motion coverage. It was published and verified on ronova.dev.

  • Known coverage: top- and bottom-directional motion where applicable, pressed feedback, and reduced-motion support.
  • Published and verified on ronova.dev; no remote D1 migration or user-data mutation ran, and the universal Ronova ID boundary remains intact.

Project seals now share one quiet card treatment.

The Ronova project directory and homepage now render every project seal through the same fully visible lower-right mask: white at 15% opacity, inside the card rather than clipped to its full height. Travel Evaluation now reuses its existing one-color Image 2 seal.

  • All current cards use the same lower-right size and inset field; each seal retains its own alpha silhouette, including the non-square Borealis mark.
  • Travel Evaluation keeps its colored SVG as the project-page mark while its catalogue card uses the existing one-color Image 2 travel seal.
  • No routes, account behavior, project access, data, or Ronova ID boundary changed.

Community now opens faster, and Messages has a focused private workspace.

Community now selects a compact, locally hosted Yuji Syuku subset for each language before falling back to the complete local font for uncommon or user-entered glyphs. Private Messages now opens as one full-height room workspace instead of public-site chrome, while its document remains no-store.

  • Messages keeps its room rail, active conversation, privacy notice, and encrypted composer in one focused window; on a phone, the room list and conversation become deliberate separate views.
  • Identity rooms label each sender as Ronova with a formatted Ronova ID; guest session messages show Guest with their opaque room-scoped session ID, never an invite capability, cookie, hash, or account identity. Before creating or joining a room, the browser checks E2EE and local-key storage, and a denied persistence grant requires explicit confirmation.
  • Yuji Syuku remains fully self-hosted under its existing OFL license; language-specific subsets reduce first-load transfer without excluding uncommon text.
  • Explicit release versions let Community and shared-shell public styles and scripts be cached immutably instead of needlessly revalidating them.
  • The immutable cache policy applies only to versioned Community and shared-shell static assets. Private Messages documents and their encryption boundary are unchanged.

Ronova Community now supports direct E2EE requests and a dedicated conversation desk.

A runtime repair restores public forum loading and authenticated participation, while private session rooms now initialize correctly with a revocable session invite. Direct E2EE message requests can now address a Ronova ID or its deterministic virtual address without changing the privacy boundary: email-style lookup does not disclose whether an account exists, and recipient approval comes before room, device, or ciphertext access. The Messages surface is a distinct Ronova conversation desk for active chats and small groups, with clear sender attribution and timestamps, designed without copying a generic consumer messenger.

  • Anyone can read forum threads, while publishing, replying, reacting, reporting, and author removals require an active human Ronova ID session; no second account system is introduced.
  • Every Ronova ID has the deterministic internal address `[email protected]` for Community addressing. It is not an SMTP mailbox and sending or receiving mail is disabled by default.
  • A direct E2EE request can start with a Ronova ID or virtual address. Email lookup is intentionally ambiguous, and recipient approval is required before room, device, or ciphertext access.
  • Private session rooms use a revocable session invite. The service stores ciphertext and limited operational metadata, not readable message bodies.
  • The first version makes its limits explicit: no attachments, cloud key recovery, forward-secrecy claim, or assurance against a compromised client.
  • Messages use a distinct Ronova conversation desk for active chats and small groups, with sender attribution and timestamps—without presence indicators, read receipts, or service access to plaintext.
  • Community layouts stack before a narrow golden-ratio shell becomes cramped, thread selections land on their labelled discussion heading, and message polling no longer reannounces earlier messages.

Omni Archon activates two bounded Ronova identity mutations.

The 252-capability catalog remains intact. Exactly two Ronova identity mutations are now usable after action-bound passkey confirmation: revoke one session belonging to another non-protected user, or compare-and-swap another non-protected account’s status among active, locked, and disabled.

  • Locking or disabling an account also revokes that account’s active sessions; neither action can target the protected human principal or the Root System.
  • ronova.dev keeps the canonical login session and identity-display authority, while id, portal, and archon receive separate host-only `__Host-` sessions through exact one-time authorization-code callbacks with signed state and PKCE S256.
  • Only verified email addresses can sign in. Verification resends are bounded, stale unverified aliases have a narrow reclaim window, and database guards preserve the last human credential and the protected owner’s final passkey.
  • Pages can reach only a signed private coordinator and executor through a Service Binding. Idempotent receipts, audit records, and resource locks are committed atomically.
  • Only the protected `000` human principal can operate these actions; the `999` Root System remains noninteractive. A UID never authorizes, and universal Ronova ID remains the sole identity system.
  • The other 250 mutation and external capabilities—including Gekka, VPN, domains, UID lifecycle, approvals and rollback, billing, and raw secrets—remain fail-closed until their executors and recovery drills are verified.

Ronova ID now uses one canonical thirteen-digit format.

Ronova ID v2 displays `AAA XXXXX XXXXX`, preserves immutable subjects and credentials, and keeps canonical identity class separate from authorization.

  • The protected human Ronova principal is exactly `000 00000 00000`; its retired identifier remains reserved history rather than a system classification.
  • The disabled Root System principal is exactly `999 99999 99999` and has no password, passkey, recovery code, session, activation path, or ordinary login route.
  • Exact saved legacy identifiers remain immutable aliases, while current surfaces copy thirteen compact digits and show the grouped identifier without wrapping.

Porta Ronovae is now the single front door.

The authenticated gateway at portal.ronova.dev now routes each Ronova ID only to destinations allowed by roles and grants; a UID prefix can prefer a door, but can never grant one.

  • One permitted destination redirects directly, several produce a destination-only launcher, and an account with no special grant returns to personal Ronova ID.
  • ronova.dev owns canonical sign-in and current-ID resolution, id.ronova.dev remains personal account and security, and external estates keep host-local sessions through exact redirect registration and authorization code plus PKCE S256.
  • The exact Root System UID remains noninteractive, the cached shell contains no personal data, and the support portal can now route Porta Ronovae requests.

Archon Panel now fails closed on protected principal authority.

The full-root Archon Panel requires the protected human Ronova principal, the global owner role, explicit Archon permission, and a strong passkey session; an ID prefix grants nothing.

  • Signed-out or missing session state returns to Account with a fixed internal continuation; eligible accounts resume Archon after login.
  • The disabled Root System identity is noninteractive, while every retired Ronova ID remains an immutable compatibility alias owned by its original principal.
  • The separate Archon access-code and content-grant surfaces remain outside the full-root panel gate.

Ronova ID now starts with a simpler sign-in choice.

Ronova ID now opens as a quiet sign-in landing: select Sign in, enter a name or UID, then choose a passkey or password.

  • The public overview was removed from the default identity route; Sign up and recovery remain alongside the sign-in flow.
  • Pages Functions are published with their shared source and D1 binding, so unavailable passkeys and failed passwords return controlled responses instead of blank pages.
  • The existing self-hosted type, color system, and universal Ronova ID boundary remain unchanged.

AI Usage now issues Archivements with Image 2 badge art.

The AI Usage route is now a multi-page collectible registry for measurable coding consequences, with 29 unique Image 2 badge faces, production derivatives, and a tested cross-agent verifier contract.

  • Added 42 nested profile, collection, family, detail, badge, methodology, verifier, ledger, and settings routes plus all eleven Tokenburner tiers.
  • Issued a unique chroma-keyed Image 2 PNG face for every record, including the 300B The Y-Axis Broke hero badge, plus hero, gallery, small, social, and locked derivatives.
  • Implemented device-local filtering, display settings, wear previews, PNG export, six verification classes, a shared evaluator, and an Ed25519 certificate-verification contract without creating a second account system.

Deploys now require a fresh Ronova build.

The deployment contract now rebuilds the site and rechecks the existing Ronova ID lifecycle before Wrangler can publish to the fixed ronova-dev target.

  • TypeScript and the Ronova ID lifecycle guard must pass before a new static build is generated.
  • The rebuilt site is validated and receives a final numbered-artifact check before publication can begin.
  • A dependency-free contract test locks the stage order and production target without changing authentication or account behavior.

Public project statuses now match verified availability.

The Projects directory now distinguishes public, maintenance, release-pending, and launch-pending work, so a label or action never outruns a verified route.

  • Fundatio's label follows its restored canonical surface, while Ronova VPN remains launch pending with no outbound portal action.
  • The universal Ronova ID remains the only account boundary for future VPN access; no second account system was added.
  • Gekka stays active with its next release pending production proof, while OpenPractice and Casino are clearly marked as maintenance surfaces.

Borealis now publishes from one verified source dossier.

The standalone Borealis Alliance dossier and seatmap generator are now the source of truth for both Ronova public routes, with a checked allowlist that prevents silent mirror drift.

  • Synchronized the dossier, public brief, and both generated TSE seatmaps to /projects/borealis/ and its /alliance/ route from one standalone source.
  • Kept all 350 and 700 editable seat placements, the constant 1:50 drawing model, local Yuji Syuku typography, and the golden-ratio presentation intact.
  • Added a build-time source contract that rejects missing, extra, or byte-different public files without changing the universal Ronova ID boundary.

Ronova ID now starts with a name-or-UID step.

The Ronova ID sign-in page now opens with a single name-or-UID field, then lets the person choose passkey or password without changing the existing font, color palette, or universal account boundary.

  • Passkey login can now narrow to the entered Ronova handle, Gekka name, UID, or email before asking the device for a credential.
  • Password fallback now sits behind the second step instead of sharing the first screen, and failed password attempts reopen the same stage with the identifier preserved locally.
  • Sign up now routes into the existing Ronova support and reviewed-request path instead of inventing a second public account system.

The Ronova footer now reads as a clearer site map.

The shared footer now separates site identity, internal routes, external destinations, and trust links into calmer columns, so public pages feel easier to scan without adding filler.

  • Identity seal now keeps the copyright line, official-site marker, and language chooser together in one place.
  • Internal Ronova routes and outward destinations now sit in separate columns, so local pages no longer compete with external links.
  • Trust links stay visible across public routes without changing the universal Ronova ID boundary or adding a second account system.

Ronova ID previously added email verification and legacy UID role prefixes.

Historically, Account Settings added verification email and visible legacy 14-digit Ronova UID handles with role-aware four-digit prefixes instead of the old universal `1000` namespace.

  • Added a real verification-email flow with signed one-use tokens, account-side resend controls, and success or expiry status messages.
  • Primary email promotion still requires a verified address, and the first confirmed address becomes primary automatically.
  • That historical four-digit classification now remains only as legacy history, while old `1000` handles stay immutable compatibility aliases.

Travel Evaluation now opens as a public archive with a Ronova ID notebook.

The canonical /projects/travel-evaluation/ route now links out to a calmer standalone website where the archive starts as read-only summary cards, each summary opens the full evaluation table on tap, published Ronova evaluations ship in the archive, and personal drafting sits behind Ronova ID.

  • The Ronova project page now acts as a launch surface only: it links to the website instead of embedding a preview, while the canonical workbench path stays /projects/travel-evaluation/workbench/.
  • The website keeps the same lounge-class, location, airline, and quality filters for a read-only archive, but now starts with summary cards only and opens the full table with exact scoring, pictures, and comments when a summary is tapped.
  • Filling in a personal evaluation now requires the existing Ronova ID boundary, and each published sheet preserves an immutable author principal plus its publication-time Ronova ID snapshot.

Travel Evaluation gets a calmer notebook-style workbench.

The same-origin Ronova workbench now feels quieter and more personal: one selected sheet at a time, softer controls, clearer accents, and browser-local travel notes for lounges, flights, and hotels.

  • The browser-local workbench at /projects/travel-evaluation/workbench/ now shows one selected sheet at a time while keeping add, filter, autosave, export/import, snapshot, and scoring behavior intact.
  • Blank text fields now open with disappearing placeholders instead of starter filler, and the dark notebook surface uses class-based accents for First, Gold, Business, Other, plus the matching flight cabin bands.
  • Kept the universal Ronova ID boundary intact: no booking layer, no review marketplace, and no second account system.

OpenPractice now has a calmer motion pass.

The OpenPractice Toolkit project page now reads more like a practice surface: a balanced hero, a small metronome swing, and quieter transitions without changing the project boundary.

  • Added a responsive metronome panel to the project hero using the existing OpenPractice mark and a reduced-motion fallback.
  • Retuned the project notes, status block, and roadmap cards so desktop gets more structure while mobile stays one-column and readable.
  • Kept the founding-phase, local-first, open-source, and Ronova ID boundary copy intact.

AI Usage opens as an open-source skill project.

The parallel-agent orchestration thought now has a Ronova project page and a public skill package for coordinating multiple Codex agents without shared-branch or port chaos.

  • Added /projects/ai-usage/ as a Ronova-side project page with a direct GitHub source link.
  • Listed AI Usage in the project directory, homepage reel, drawer project list, sitemap, and encrypted support context selector.
  • Kept the project as an operating skill and documentation layer: no second account system, no automatic deploy authority, and no hidden production actions.

Borealis redrew the TSE seatmaps at a constant 1:50 ratio.

The embedded TSE Rail seatmaps were rebuilt around a real 1:50 drawing ratio, cleaner top-down cabin modules, and much smaller close-up-inspired seat symbols so the furniture-to-carriage proportion reads closer to life size.

  • Reset the generator to a constant 1:50 ratio across carriage, zone, and seat footprints.
  • Rebuilt the four reusable class symbols from the supplied close-up design language, then reduced the rendered furniture size strongly inside each measured footprint while keeping every passenger place editable and every second Magna placement flipped horizontally.
  • Synced the redesigned SVGs and refreshed Borealis copy through /projects/borealis/ under a fresh shared static asset key, without introducing any second account system.

Borealis now balances its first viewport on wide desktop.

The broader Borealis dossier shell now gains a real wide-screen composition: the hero copy, seal field, and highlight strip align as one stage instead of simply stretching farther.

  • Added an ultra-wide layout state so the hero copy sits on a deliberate left track while the right side stays reserved for the seal and atmospheric line work.
  • Retuned the highlight strip with a slightly deeper overlap and steadier column balance for the wider desktop stage.
  • Kept ordinary desktop, tablet, and mobile behavior intact; the new composition only engages once the viewport genuinely has room.

Borealis now uses a broader dossier shell.

The direct Borealis dossier no longer sits in a narrow center column on large screens; its shared shell now stretches much further across the page while keeping readable text measures.

  • Raised the shared dossier width cap so the nav, hero, stat strip, and section bands all use the same broader shell.
  • Kept headings and paragraphs locally constrained inside that shell so the page reads comfortably instead of turning into a wall of text.
  • Bumped the shared static asset key so /projects/borealis/ and the standalone dossier refresh to the wider layout instead of holding the cached narrow copy.

Borealis refined the TSE seat icons.

The Borealis dossier now carries editable TSE Rail seatmaps where every passenger place remains editable, while the drawn artwork is copied from one detailed TSE-8-inspired iconic SVG seat per class.

  • Rebuilt the Optimized and Compact SVGs with four reusable class icons copied into 700 and 350 editable placement groups.
  • Held lavatories and service points to a constant 1:50 passenger-facing ratio in both candidates.
  • Redrew the Magna icon with a reduced-length seat, same-width side table, panel lines, table marker, and every second placement flipped horizontally.
  • Shipped the generated SVG drawings and brief beside the direct Borealis dossier at /projects/borealis/ without adding any second account system.

Project directory links were made concrete.

The public links and project cards now avoid fake actions: Projects points to the directory, VPN opens the Triluna-hosted portal, and exploratory cards are no longer shown in the directory.

  • Changed the official project-reference card into a Projects directory link.
  • Connected Ronova VPN to `https://vpn.triluna.org/` while preserving the universal Ronova ID boundary.
  • Removed Scriptura and Experiments from the public project cards until each has a concrete destination or page.

Borealis now has a full project page.

The Borealis card now opens the complete Borealis Alliance HTML dossier directly on the Ronova route.

  • Extracted the compact embedded Borealis logo from the standalone Borealis Alliance page.
  • Added the seal to the homepage project reel and Projects directory as a low-opacity CSS background.
  • Made /projects/borealis/ the direct public dossier route, while preserving the universal Ronova ID boundary and framing Borealis as a concept rather than a live service.

Ronova VPN moved to vpn.triluna.org.

The VPN portal is now registered as a Triluna-hosted Ronova ID redirect-code client instead of a Ronova subdomain surface.

  • Moved the Ronova ID app and client registry for `ronova-vpn` to `https://vpn.triluna.org`.
  • Changed the VPN callback to `https://vpn.triluna.org/api/auth/ronova/callback` with redirect-code exchange.
  • Kept the universal Ronova ID boundary: the VPN uses existing linked account records and does not add a second account system.

OpenPractice Toolkit is now listed on ronova.dev.

The open-source music practice bootstrap now has a public Ronova project page, project-directory card, support-routing context, and localized route coverage.

  • Added /projects/open-practice-toolkit/ as the Ronova-facing project page with links to the public GitHub repository.
  • Added OpenPractice Toolkit to the homepage project reel, Projects directory, drawer project list, sitemap, and encrypted support context selector.
  • Kept the project local-first and open-source in framing, with no second account system or paid API requirement for core practice features.

Roulette Probability Lab lands under Casino Statistics.

The roulette module is now a standalone educational simulator with a playable table, visible wheel, rolling ball, seeded simulations, strategy bots, and no-money guardrails.

  • Added /projects/casino/roulette/ as a static public lab for European and American roulette probability analysis.
  • Kept the module single-player and offline in behavior: no payments, no accounts, no deposits, no withdrawals, and no casino connection.
  • Published the requested muted matcha, sakura, dark-wood, and burgundy interface with expected value, bias testing, debug mode, and charts.

月影銅円台 opens as the Pascal coin-pusher module.

Casino Statistics now presents the recursive Pascal coin pusher as a slower physical simulator with an A-frame belt lift, level baskets, table drains, labelled entries, larger equal bonus Pascal boards, compact coin controls, and an optional blueprint guide.

  • Refreshed /projects/casino/coin-pusher/ so the embedded 3D 月影銅円台 simulator is the first-screen focus.
  • Added continuous staggered coin motion with contact bounces, ordinary holes draining to the table, a right-half lever into the left lift basket, diagonal belts, M/G entry gates, connected n=3/n=4/n=5 bonus layers, a tiny final fork, and a 10-coin throw.
  • Slowed falling and elevator travel, shrank visible coins to 75%, moved bonus credit into physical G-entry drops, and added a large burgundy bonus burst that blurs away.
  • Added a default-off blueprint guide that traces sample paths, catch baskets, X chutes, and label lanes without changing seeded outcomes or payouts.
  • Unified simulator typography on Yuji Syuku only, including the bonus burst and canvas-rendered board labels.
  • Preserved the no-money boundary: virtual copper coins only, no deposits, no withdrawals, no gambling account.

Casino Statistics opens as a no-money simulator.

The new Casino Statistics project route explains house edge with virtual chips, expected value, and short-run variance before any future game modules are added.

  • Added /projects/casino/ as a localized Ronova project page with a playable virtual-chip simulator.
  • Added Casino Statistics to the project directory, homepage reel, drawer project list, and encrypted support routing.
  • Kept the project separate from Ronova ID account flows and real-money payments.

Archon now anchors the three website roots.

Ronova, Gekka, and Triluna now share one owner/root control model: regular account management stays on id.ronova.dev, while archon.ronova.dev is the only root control plane.

  • Added a website-root registry for ronova.dev, gekka-harae.com, and triluna.org with root control pointed to archon.ronova.dev.
  • Registered Triluna / Fundatio as a Ronova ID redirect-code client without creating a second account system.
  • Added Fundatio / Triluna to support routing and refreshed the owner-only Archon dashboard to show the three public roots.

Ronova ID now has a complete self-service recovery path.

Ronova ID now supports direct account creation, one-time recovery codes for password recovery, and a clear support route when a passkey is lost, while passkeys remain the strong-session method for sensitive actions.

  • Historically, first-party Ronova ID sign-up generated a legacy 14-digit player UID and showed recovery codes exactly once at creation.
  • Added a one-time recovery-code password reset flow that revokes prior sessions before opening a new standard session.
  • Added dedicated id.ronova.dev sign-up and recovery routes, including a support handoff for lost passkeys, without introducing a second account system.

Ronova ID sign-in resolves the staged name-first flow again.

The live auth routes were restored with their Pages Functions, display-name lookup now matches the staged name-first entry field, and the dedicated identity host keeps rewritten return paths aligned with the staged passkey and password controls.

  • Restored the live `/api/auth/*` and `/api/identity/*` surface by redeploying the Ronova bundle from the project root so Pages Functions ship together with the static build.
  • Broadened Ronova ID identifier lookup so an exact account display name can resolve the same staged passkey and password flow as handle, UID, migrated Gekka name, or email.
  • Rewrote `data-redirect-to` values for `id.ronova.dev` HTML so passkey and password returns stay on `/` and `/account/` instead of leaking fallback `/id/*` paths.

Crawl metadata now has a guarded owner.

The robots.txt response now comes from an exact Pages Function with a shared source, while the remaining live cache mismatch is isolated to a Cloudflare zone cache rule.

  • Moved the canonical robots body into one shared source used by the Pages Function and validators.
  • Changed the build so public/ and dist/ cannot quietly reintroduce a static robots.txt asset.
  • Confirmed the latest Pages preview serves max-age=0 while ronova.dev still needs a Cloudflare zone cache-rule change.

The menu now points to active projects and Account.

The drawer now lists active project entries under Projects and adds an Account path under Access for Ronova ID sign-in and sign-up flows.

  • Projects in the drawer now come from the active and experimental project cards instead of a separate hand-maintained shortcut.
  • Access now includes Account, linking to the existing Ronova ID account page rather than creating a second account system.
  • AGENTS.md now records that new projects must also be added to the feedback/support form routing options.

Encrypted support now has its production key.

Ronova.dev now builds the support form with the real public ECDH key, keeps the private key local, and validates that the encrypted form cannot quietly ship disabled.

  • Loaded PUBLIC_ENCRYPTION_KEY from the local public JWK during the site build when no environment value is supplied.
  • Added a built-site validator check for a configured P-256 public key, the encrypted submit button, and no private key material in the page.
  • Refreshed the shared static asset key for the deployed support surface.

Project previews now loop one at a time.

The homepage project section now contains every project in a single-card horizontal reel with dot/status hints and a seven-second auto-advance loop.

  • Removed visible carousel buttons and the scrollbar while keeping natural horizontal scrolling.
  • Added dots plus a current-project line so the active card is visible without instruction text.
  • Made the reel advance every seven seconds and repeat from the beginning.
  • Moved both the Gekka Harae logo and Fundatio Trilunae seal into low-opacity monocolor project-card backgrounds.

Ronova ID and access copy are clearer.

The identity portal now explains who can receive a Ronova ID, labels password fallback fields visibly, and keeps access-code guidance fully localized.

  • Added visible labels, helper text, and custom validation messages for Ronova ID password sign-in.
  • Clarified that Ronova ID is issued by invitation, migration, or reviewed request, without adding a second account system.
  • Localized access-code caution text and tightened mixed-language project labels across the public site.

Public role wording now keeps one identity line.

The public i18n copy now keeps Ronova's feminine role wording consistent where the language marks gender, while leaving Ronova ID and account flows unchanged.

  • Changed German public role copy to feminine forms for developer, student, and creator.
  • Aligned French creator-side Gekka wording with the existing feminine `créatrice` identity line.
  • Kept Japanese and Traditional Chinese role phrasing natural in their existing non-gendered grammar, and rebuilt the public i18n CSV.

Ronova ID UID labels now use grouped display.

Historically, visible Ronova ID surfaces grouped legacy 14-digit UID handles as `UID: 1000 12345 67890`; account and admin routes remained task-focused.

  • Formatted UID handles in account settings, controlled Archon admin, Archon redemption status, sign-in status, and passkey enrollment labels.
  • Kept raw UID identifiers unchanged for login lookup, storage, and API contracts.
  • Left the full Ronova ID overview on `/id/` and kept `/id/account/` plus `/id/admin/` as task-focused subpages.
  • Made button controls explicitly use Yuji Syuku and kept identity panels in one-column reading flow.

Archon access codes now support guest and Ronova ID redemption.

The Archon surface can issue codes with a shared seat limit, ten-minute guest reservations, account-bound Ronova ID grants, optional ID-only viewing, and owner-side revocation.

  • Added a dedicated Archon access-code model with hashed codes, account grants, guest reservations, and D1-enforced seat limits.
  • Anonymous redemption now blocks one seat for ten minutes instead of creating a long private session.
  • Ronova ID redemption binds authorization to the account so active sessions for that account can view authorized content until revoked.
  • Extended the owner-only controlled Archon with distribution, code revocation, and account-grant revocation controls.

The public website now favors one-column reading.

Major public layouts now stack into one calm reading column across desktop, tablet, and mobile while compact controls, tags, and buttons keep their natural inline behavior.

  • Flattened split grids, project lists, devlog entries, drawer sections, footer groups, Fundatio panels, and Ronova ID card surfaces into single-column stacks.
  • Removed the wide-desktop project-card grid so project pages and homepage project excerpts keep the same reading rhythm.
  • Kept small control rows such as tags, buttons, filters, and form choices flexible without turning page content into columns.
  • Preserved existing routes, Ronova ID, access logic, and localized content structure.

The public website layout was tightened for reading.

The public site now uses calmer hero structure, steadier project cards, readable devlog cards, and sturdier responsive controls without changing Ronova ID or access logic.

  • Unframed the homepage's main hero copy so the first screen reads as the creator hub rather than a stacked card.
  • Reworked devlog entries into full-width cards with a date/tag rail and a readable content column.
  • Refined project-card spacing while keeping the public reading path stable.
  • Replaced viewport-scaled heading sizes with steadier responsive steps and removed negative heading letter-spacing.
  • Separated access-form actions from hero actions so localized button text has a safer row.

Ronova ID password login now stays in the login flow.

Failed password sign-in no longer strands the browser on a raw API JSON page, and migrated Gekka usernames historically resolved beside an explicit legacy 14-digit Ronova UID.

  • Browser form failures redirect back to Ronova ID with a readable status message.
  • API and fetch callers receive `login-failed` with a safe status code and redirect target.
  • Historically imported Gekka usernames retained legacy password credentials, mapped old ten-digit UIDs to explicit legacy 14-digit Ronova UID aliases, and kept email aliases on the existing Gekka HMAC lookup format.
  • Removed the browser-only 12-character password gate from sign-in so migrated Gekka legacy passwords reach server verification.
  • Password sign-in now keeps the original authorization continuation path so registered apps can resume after login.

Gekka login transfer now lands under Ronova ID.

Gekka Account keeps player records and saves, while sign-in authority now belongs to Ronova ID instead of a separate Gekka login.

  • Updated the Gekka Account bridge to accept standard Ronova ID sessions for ordinary sign-in, including the managed password fallback.
  • Kept transfer and recovery-sensitive actions behind strong passkey-backed Ronova ID trust.
  • Aligned visible Gekka Account language around transferring login authority to Ronova ID.

The public i18n CSV now covers the five-language set.

The public text export now draws catalog, static shell, and admin-visible copy from localized sources across English, German, French, Japanese, and Traditional Chinese.

  • Moved Ronova ID catalog labels, static shell text, structured-data terms, vCard text, and admin-console labels into localized source objects.
  • Regenerated `ronova-public-i18n.csv` with 5,548 localized rows and no English-only status entries.
  • Refined the drawer and contact-card language so public paths read as orientation and confirmation rather than procedural instruction.

Ronova ID now has managed legacy password login.

Account Management can set or disable a password fallback, remove passkeys only when another credential remains, and review recent login history.

  • Added `legacy-password` login for accounts that enable a password in Account Management.
  • Added Add Passkey and Remove Passkey controls with last-credential protection.
  • Added account login history for passkey, password, bridge, and logout events.

Fundatio's outward action was tightened.

The Fundatio bridge now keeps a single visible triluna.org button in the first viewport and gives the external label stronger contrast.

  • Removed the repeated triluna.org button from the side panel so the page no longer presents duplicate outward CTAs in the same view.
  • Kept the page relationship text intact while leaving the hero as the single handoff to triluna.org.
  • Strengthened the primary-button external chip so the label reads clearly against the lavender-gold gradient.

Ronova ID now coordinates the Ronova subdomains.

This entry records an earlier shared-session phase. The 2026-07-18 host-only authorization-code cutover supersedes that design.

  • Archived the earlier same-site coordination phase for release history; it is no longer the active session architecture.
  • Registered `ronova-archon` and `ronova-vpn` in the identity app/client catalog and D1 migration.
  • See the 2026-07-18 entry for the current isolated host-session and one-time code flow.

Archon and VPN subdomains are now live on Cloudflare.

The dedicated `archon.ronova.dev` control host and `vpn.ronova.dev` portal host now resolve through Cloudflare Pages instead of stopping at missing DNS.

  • Added the required proxied Cloudflare CNAME routes for the archon and VPN Pages projects.
  • Confirmed `archon.ronova.dev` serves the owner-only control plane with no-store/noindex headers.
  • Redeployed the Ronova VPN Pages bundle and verified `vpn.ronova.dev` serves the Ronova VPN Portal while the pages.dev host redirects to it.

Fundatio Trilunae now sits under Projects.

The homepage now treats Fundatio Trilunae as a project entry instead of a separate feature band, with a transparent seal and a Ronova-side project page.

  • Moved the visible Fundatio entry into the existing Projects card list instead of keeping a standalone homepage section.
  • Linked the card to `/fundatio/` as a project description, while keeping `https://triluna.org` as the external Fundatio site target.
  • Replaced the white-disc seal treatment with a transparent seal asset rendered directly on the project card.

The controlled archon now lives at archon.ronova.dev.

The owner-only control plane now uses a dedicated subdomain, with old admin paths redirecting there and the same passkey-required access-key, grant, private-page, registry, and audit controls.

  • Added `archon.ronova.dev` as the canonical controlled-archon host and redirected `/id/admin/` plus `id.ronova.dev/admin/` there.
  • Access keys can now be issued once, stored only as keyed hashes, and revoked together with their active private-page sessions.
  • `/api/admin/archon` is host-gated to the archon surface and still requires the global owner role plus a strong passkey-backed Ronova ID session.

The Gekka page and drawer navigation were simplified.

The project page now states the creator-hub and official-site boundary faster, while the overlay menu is calmer, lower density, and easier to scan.

  • Rebuilt the drawer around Main, Projects, Access, Language, External, and Trust so primary paths are no longer buried in a dashboard-like sitemap.
  • Rewrote the Gekka page copy to keep Ronova.dev as creator context while sending official information, versions, and entry points to gekka-harae.com.
  • Reduced footer repetition to copyright, site identity, language, the official project site, and essential trust links.

The deploy gate now checks mutable public asset cache keys.

Generated pages now fail validation if public scripts, styles, social images, favicons, or the contact card bypass the shared cache-busting version.

  • Access, support, and contact-card pages now use the shared static asset version for their route-level assets.
  • The built-site validator scans every generated HTML file for unversioned mutable public assets before release.
  • The static header policy now also requires `X-Content-Type-Options: nosniff` on the public contact card.

Ronova ID now gates recovery-sensitive settings behind step-up.

Recovery-adjacent account settings now require a strong passkey-backed Ronova ID session when the identity is marked for step-up.

  • Email add, primary-email changes, email removal, passkey disabling, and other-session revocation now return `step-up-required` unless the session is strong.
  • Passkey enrollment and profile-only edits stay available so bootstrap can move forward without adding a password fallback.
  • The account settings panel now reflects the blocked state and keeps password login unavailable.

Ronova ID account settings are now a real self-service surface.

The Ronova ID account view now loads live settings for profile details, emails, passwordless status, passkeys, active sessions, recovery posture, and app access.

  • Added authenticated settings APIs for profile updates, unverified email rows, passkey disabling, and other-session revocation.
  • Kept password management explicitly passwordless: Ronova ID does not create or store a password.
  • Added a live account settings panel on the Ronova ID account page with cache-busted scripts and styles.

Ronova ID now has a live passkey sign-in path.

The identity runtime now has WebAuthn challenge storage, passkey enrollment, passkey sign-in, and stronger exchange trust fields so cross-project clients can tell when a Ronova ID proof was backed by a user-verified passkey.

  • Added the `0004_ronova_passkey_runtime` D1 migration for WebAuthn challenges and passkey credential metadata.
  • The Ronova ID account page now offers passkey sign-in and passkey enrollment while keeping the legacy bridge as a narrow owner bootstrap.
  • Authorization-code exchange now reports passkey-backed trust fields for future Gekka Account validation.

Ronova ID is now framed as a cross-project account layer.

The identity registry now names account.gekka-harae.com as its own Gekka Account Center client, so the Gekka project has a concrete Ronova ID target for sign-in and login transfer.

  • Added a dedicated `gekka-account` app and client for `https://account.gekka-harae.com/api/auth/ronova/callback`.
  • Added `gekka.account.login`, `gekka.account.link`, and `gekka.account.recovery` permissions to separate account identity from play, Senate, and Archon authority.
  • Updated the architecture note so Gekka can transfer login authority to Ronova ID without treating a Gekka session as a Ronova private-page session.

Ronova ID has a full shared-identity design.

The Ronova ID architecture note now spells out the intended passkey-first identity system for ronova.dev, id.ronova.dev, and related projects, including D1 schema direction, recovery, private-page access, and Gekka permission bridging.

  • Documented Ronova ID as the central identity plane while keeping each consuming app on its own scoped session.
  • Defined the long-term D1 model for users, passkeys, WebAuthn challenges, recovery codes, access keys, app grants, sessions, tickets, and audit events.
  • Clarified that Gekka account flows may request Ronova permissions, but private ronova.dev pages unlock only through explicit Ronova ID grants and short-lived audience-bound tickets.

Subpages were refined with a security-aware polish pass.

ronova.dev received a focused refinement pass across public presentation and runtime handling: the homepage status panel is now localized, trust pages read more cleanly, devlog tags are easier to scan, and Ronova ID request parsing follows the bounded-body pattern used by the older access and support endpoints.

  • Localized the homepage status rail so non-English surfaces no longer show hardcoded English labels in the first viewport.
  • Tightened the devlog and trust-page presentation with scannable tags and calmer note panels.
  • Bounded Ronova ID auth request-body parsing for JSON and URL-encoded form submissions before login, logout, and code exchange handling.

Ronova ID now has its own subdomain route.

id.ronova.dev now routes into the existing Ronova ID portal instead of leaving the identity host as an unwired future address.

  • Added host-aware Pages routing so the identity overview, account view, and admin view can be served from `id.ronova.dev`, `/account/`, and `/admin/`.
  • Kept `ronova.dev/id/` as the path fallback while declaring the dedicated identity hostname in the public app catalog.
  • Preserved the noindex and no-store posture for Ronova ID while redirecting unrelated subdomain paths back to the main public site.

Ronova ID foundations now exist as real public surfaces and runtime APIs.

ronova.dev now exposes a first-pass Ronova ID foundation with dedicated identity pages, a central app and client registry, and the start of a redirect-based authorization flow that keeps sessions scoped per application.

  • Added real `/id/` and `/id/account/` surfaces plus the admin source route that now redirects to `archon.ronova.dev`, with localized variants for English, German, French, Japanese, and Traditional Chinese.
  • Seeded a central Ronova ID D1 registry for first-party apps, trusted clients, roles, permissions, sessions, authorization codes, and audit events.
  • Shipped the first migration-safe bootstrap path: a narrow legacy Ronova private admin bridge that can create the initial owner identity session without turning cross-domain cookies into the trust model.

Navigation now separates primary paths, deeper routes, and trust links.

The public shell now keeps the header focused, moves the full site map into a real right-edge drawer, and grounds the footer in contact, official verification, and trust metadata.

  • Reduced the always-visible header to identity, the main public pages, a direct access action, and a far-right hamburger trigger.
  • Built a full-height right-side drawer at the site layer rather than inside the header band, with keyboard handling, focus return, backdrop closing, and reduced-motion-friendly behavior.
  • Reworked the footer so contact routes, official external verification, and trust links stay visible without permanently exposing the public phone number.

Project routing now steps through Ronova pages first.

The public project flow now introduces work on ronova.dev before sending people outward, while the footer regains a direct `gekka-harae.com` shortcut for anyone who already knows where they want to go.

  • Changed the Gekka entry on the Projects surface so it opens the Ronova bridge page instead of jumping straight to the external site.
  • Restored the Gekka bridge page's outward button so the description page can hand off to the official project website explicitly.
  • Added `gekka-harae.com` back to the footer's external-link group as a direct destination.

Contact-card downloads now pause at a plain-language checkpoint.

The footer and contact surfaces no longer trigger the address-book file immediately. They now open a review page that explains the card's contents before the download starts.

  • Replaced direct contact-card downloads in the footer, contact page, and official-link cards with one shared review route.
  • Listed the real saved fields in human language: name, email, telephone, official site, GitHub profile, Bilibili profile, and the short site note.
  • Kept the actual .vcf file available only behind an explicit confirm-and-download action.

Scroll reveals now breathe instead of jumping.

Cards, panels, and text sections now track a reusable 0-to-100% viewport-edge reveal scale, resolving smoothly through the top and bottom ten percent of the screen.

  • Replaced the old one-shot load animation with a shared scroll-progress reveal system.
  • Mapped reveal progress from 0% to 100% inside the top and bottom 10% viewport bands instead of flipping blocks fully on or off.
  • Kept the blur-led pixel resolve so text boxes and cards still clear in gradually while scrolling down, back up, and through reshuffled project listings.

Language switching moved out of the header.

The header now stays focused on primary navigation, while language selection moved into a secondary native pull-down in the footer with its own globe-marked control.

  • Removed the language switcher from both desktop and mobile header states.
  • Added a footer language pull-down built with native HTML details and summary instead of reusing the previous built-in switcher.
  • Kept language choice under the copyright block so the footer remains the single place for route-level utilities.

Outward links were confined and the footer was grounded.

Project destinations now stay on the dedicated Projects page, platform links were gathered into the footer, and short pages keep their empty space above the footer instead of below it.

  • Removed direct external jumps from the homepage hero, featured project cards, contact-page actions, and the Gekka bridge page.
  • Split the footer into separate identity, internal-link, and external-link columns, with language links directly under the copyright line.
  • Changed the page shell so the footer stays at the bottom of the viewport on shorter pages.

Public contact links were expanded.

The public contact surfaces now carry a live Bilibili profile, a Swiss telephone line, and a refreshed contact card instead of keeping social contact partially hidden.

  • Replaced the remaining social slot with the official Bilibili profile for Ronova27.
  • Added the public telephone number across the contact page, footer, structured identity metadata, and tap-to-call links.
  • Updated the downloadable .vcf card so saved contacts now include both the telephone line and the Bilibili URL.

Identity signals were tightened for search engines.

Public metadata, profile schema, sitemap coverage, and protected-route crawl blocking were aligned so ronova.dev reads more clearly as Ronova Deng’s official site.

  • Added a stronger ProfilePage plus Person graph tying together Ronova, Ronova Deng, ronova.dev, GitHub, and gekka-harae.com.
  • Cleaned the alternate-language graph and added the public devlog routes to the sitemap so fresh public content is easier to discover.
  • Applied X-Robots-Tag noindex headers to /private/* and /api/* so protected surfaces stay outside search indexes.

The public palette moved into a dusk-and-amethyst register.

The shared shell now carries a deeper ink palette with amethyst and moon-gold accents across navigation, cards, forms, and social assets.

  • Replaced the old blue-forward shell tokens with a cohesive Deep Ink, Amethyst, and Moon Gold palette in the shared stylesheet.
  • Carried the same palette through buttons, status pills, form controls, and the private access shell so the runtime no longer drifts from the public pages.
  • Updated the favicon, social card, and browser theme color so shared assets match the live site instead of keeping the previous palette.

Project naming was normalized by language.

Visible project naming now comes from a shared expression table, so Latin-script pages keep Gekka Harae while Chinese surfaces keep the native-script title without mixed labels.

  • Added one shared expression table instead of repeating mixed-script project names across locale files.
  • Updated English and German copy to use Gekka Harae, while Traditional Chinese keeps the native-script title on visible labels.
  • Kept technical identifiers like gekka-harae.com unchanged while cleaning headings, metadata, and support options.

The public shell went live.

ronova.dev now runs as a multilingual Astro site with a clean public shell, dedicated project routing, and a real Cloudflare Pages delivery path.

  • Built the first public shell with English, German, and Traditional Chinese route support.
  • Split creator-hub pages from project-destination pages so ronova.dev and gekka-harae.com each keep a clear role.
  • Verified the custom-domain path for ronova.dev on top of the Pages project.

Private contact and access were hardened.

Support and private access moved beyond static-only scaffolding into a server-backed flow with encryption, scoped sessions, and D1-backed validation.

  • Added browser-side encryption for support submissions before message storage.
  • Kept private pages behind scoped access codes with server-validated session handling.
  • Verified the request path against the local Pages runtime instead of trusting static-only assumptions.

Typography and layout received a tighter pass.

The site’s visual pass focused on consistency: one font family, a corrected responsive grid, and a cleaner production-ready shell.

  • Switched the public typography to Yuji Syuku across the main site and social card asset.
  • Fixed the shared project-card rhythm so tablet Safari keeps the intended full-width reading layout.
  • Rebuilt and redeployed after the layout correction to confirm the production path.