Goal
Prepare the repository and validation contract for a future parallel Cloudflare Pages custom domain:
\ ools.securetools.app → secure-tools-web-bridge`n
This issue covers the preparation PR and the later activation gate. The first run stops before custom-domain attachment or DNS changes.
Preparation scope
- document activation order, TLS/DNS invariants, rollback, SEO isolation, and the manual browser QA gate
- extend bridge validation so the custom domain can be validated after activation without making the pre-activation PR predictably fail
- preserve the stable \secure-tools-web-bridge.pages.dev\ endpoint
- keep \securetools.app\ on its existing GitHub Pages deployment unchanged
Activation gate
Before attaching the custom domain, require human browser QA on the Pages bridge: one PDF operation, one image operation, one metadata operation, and Network-panel confirmation that selected files are not uploaded.
Non-goals
No DNS or custom-domain change in the preparation run; no apex, CNAME, Search Console, canonical, og:url, sitemap, redirect, GitHub Pages, application behavior, H3.4, or v3 changes.
Goal
Prepare the repository and validation contract for a future parallel Cloudflare Pages custom domain:
\ ools.securetools.app → secure-tools-web-bridge`n
This issue covers the preparation PR and the later activation gate. The first run stops before custom-domain attachment or DNS changes.
Preparation scope
Activation gate
Before attaching the custom domain, require human browser QA on the Pages bridge: one PDF operation, one image operation, one metadata operation, and Network-panel confirmation that selected files are not uploaded.
Non-goals
No DNS or custom-domain change in the preparation run; no apex, CNAME, Search Console, canonical, og:url, sitemap, redirect, GitHub Pages, application behavior, H3.4, or v3 changes.