React and TypeScript Web foundation for the ArcForges family. This first increment contains a public Hello World site, an interactive local greeting, shared UI, published Contracts consumption and an automated Cloudflare Workers Static Assets delivery pipeline.
It does not implement the planned Account/Chat application, authentication, payments or a C# backend. The /hello/ greeting runs locally and sends no name to a server. A separate /cloud-hello/ page uses the published gRPC-Web client to call the deployed Cloud container after the user clicks Check connection. Business authority remains in ArcForges Cloud.
Use Node 24.21.0 / npm 11.19.0, matching .node-version and packageManager.
npm ci --ignore-scripts
npm run hooks
npm run devOpen the local URL printed by React Router. Public pages are rendered at build time; there is no request-time Node server in the deployed artifact. A small Cloudflare Worker redirects www.arcforges.com to the canonical HTTPS apex before serving pages; other requests use the static asset binding.
npm run check
npm run build
npm run previewThe preview serves the actual candidate through local Wrangler at http://127.0.0.1:4173. Browser checks are explicit local opt-in only when existing browser binaries support the affected behavior; do not install browsers to expand validation. No Cloudflare login is required for preview.
| Path | Purpose |
|---|---|
apps/site |
Prerendered home, local greeting and server connection pages |
apps/app |
Documented boundary for the future Account/Chat profiles |
packages/ui |
Shared components and Tailwind/CSS styles |
worker |
Private canonical-host redirect and static asset fallback |
tooling |
TypeScript build, provenance, policy and Cloudflare delivery commands |
tests |
Unit, published SDK wire fixtures, browser and accessibility tests |
artifacts/candidate |
Ignored immutable delivery artifact, manifest and SBOMs |
win.slnx / ArcForges.Web.esproj |
Optional Visual Studio JavaScript project |
Baseline: TypeScript 7.0.2, React 19.3.0, React Router 8.4.0, Vite 8.3.0, Tailwind 4.3.3, Wrangler 4.135.0. One committed npm lockfile covers the entire workspace. Contracts packages are pinned to 1.0.0-ci.44.1; no submodules or adjacent source references are used.
PRs run source/static/offline checks, Windows IDE declaration evaluation, security scans and one Linux candidate build containing the prerendered assets and redirect Worker. Main deploys those same bytes and records provider completion in a GitHub prerelease. CI does not install browsers, run E2E, fetch public assets or call Cloud. See validation policy. Private workspaces are not published to npm; Workers subdomains and preview URLs remain disabled.
The main-only GitHub cloudflare environment contains the account variable and deployment secret. Domain bindings are managed in Cloudflare; CI verifies that the apex custom domain belongs to this Worker before deploying. Preserve the existing www.arcforges.com/* Web route and its proxied DNS record. The redirect retains the path and query, so a new visit to the www connection page reaches the apex before its same-origin Cloud call. PR checks remain credential-free. See deployment setup and recovery and evidence.
Workers Static Assets serves the static React build behind the canonical-host redirect. Frameworks that need request-time rendering require a Workers-compatible adapter/runtime. This setup does not host C# or provide an API proxy. The Cloud Worker owns arcforges.com/api/* and forwards to its Native AOT container; see the Hello integration boundary and Cloud ownership. See also the official React guide and static assets guide.
The build and CI enforce the project licence declarations across every npm workspace and the JavaScript IDE adapter. They also enforce source and actual browser artifact provenance, including complete legal notices, immutable reuse records and the emitted browser SBOM.
Read development, contributing, security, validation, and the bootstrap plan.
The existing repository license is AGPL-3.0-only; see LICENSE. Upstream Contracts and other dependencies retain their own licenses. The built site exposes the license, source link and generated third-party notices. See third-party notices.
The sealed build identity is available at /__build-info.json for explicit support diagnostics; CI seals it from independent inputs without a browser runtime.