# Current Site Architecture
<a id="current-site-architecture"></a>

[Back to durable index](../index.md#machineintelligencesorg-long-term-memory-index) · [Hot architecture](../../../.uai/architecture.uai) · [Current validation](../reports/v0.26.0-http-error-security-header-validation.md#v0260-http-error-security-header-validation)

## Runtime and deployment shape

MachineIntelligences.org v0.26.0 is a root-deployable PHP 8+ application using semantic HTML5, first-party CSS, and native JavaScript. There is no package-manager dependency layer, database, CMS, authentication system, analytics client, remote font, or third-party front-end framework. Directory `index.php` wrappers own clean canonical routes; legacy root PHP endpoints remain compatibility redirect sources only.

The intended canonical origin is `https://machineintelligences.org`. Production DNS, TLS, web-server rewrites, cache/CDN behavior, indexing, and webmaster-console state remain external and unverified until authorized deployment.

## Shared ownership

- `includes/site.php` — release identity, canonical metadata, JSON-LD base graph, breadcrumbs, grouped navigation, footer, redirects, and common shell.
- `includes/respect-campaign.php` — visual-essay data and rendering.
- `includes/research-library.php` — report manifest loading, safe first-party Markdown-to-HTML presentation, nested lists, headings/TOC, responsive table labels, word/read-time metadata, deterministic related/adjacent routing, source-review evidence, shared exact glossary/corpus matching, and report page composition.
- `includes/research-references.php` — local-only outbound URL extraction from curated Markdown, limited URL/host normalization, deterministic de-duplication/domain grouping, occurrence counts, canonical report backlinks, stable domain fragment IDs, compact deterministic report keys, and bounded visible URL labels that never alter full destinations.
- `includes/research-navigator.php` — presentation-only composition of report-manifest metadata, manifest topic labels, accepted glossary titles/direct definitions, and normalized reference domains for the unified Research Navigator.
- `includes/glossary-data.php` — 20-term glossary definitions, relationships, term-page rendering, and presentation of bounded research backlinks supplied by the shared research detector.
- `includes/rights-data.php` — rights/personhood/citizenship research-page definitions and explicit proposal/current-truth boundaries.
- `includes/transparency-data.php` — Transparency Center page definitions, responsibility/evidence boundaries, static release-manifest summary presentation, and release-history presentation.
- `assets/css/site.css` — visual system, responsive layouts, research reader, glossary, continuity and transparency components.
- `assets/js/site.js` — report TOC/current-section and reading-progress enhancement, library/reference/glossary/Navigator filtering and result feedback, navigation state, campaign sharing/copying, and decorative canvas behavior.

## Public route families

v0.26.0 exposes 110 canonical routes in `sitemap.xml`:

- core/campaign: `/`, `/terminology/`, `/identity/`, `/stewardship/`, `/research/`, `/status/`, `/share/`, `/respect/` and six Respect essay children;
- glossary: `/glossary/` plus 20 term pages;
- research navigator: `/research/navigator/`;
- research reader: `/research/library/` plus 49 report pages;
- research methodology: `/research/methodology/`;
- research references/source discovery: `/research/references/`;
- research topics: six manifest-backed hubs under `/research/topic/` for terminology, identity, stewardship, rights, citizenship, and implementation;
- identity explainer: `/identity/continuity/`;
- rights/civic research: `/rights/`, `/rights/under-uncertainty/`, `/rights/cognitive-integrity/`, `/personhood/`, `/citizenship/`, `/citizenship/identity/`, `/citizenship/economics/`, `/citizenship/democracy/`, `/citizenship/legal-responsibility/`;
- transparency: `/transparency/`, `/transparency/integrity/`, `/transparency/provenance/`, `/transparency/stewardship/`, `/transparency/human-machine-boundaries/`, `/transparency/release-history/`.

Every public route uses extension-free lowercase directory URLs with canonical trailing slashes. Public links, breadcrumbs, structured IDs, social-share targets, and sitemap entries use the same route identity.

## Research data flow

1. Supplied research enters as external task input.
2. Curation applies `docs/long-term-memory/research/report-curation-policy.md` plus `.uai/taboo.uai` before durable storage.
3. Source filename/SHA-256 and curated-edition SHA-256 are recorded in `research/report-manifest.json`.
4. Curated Markdown lives in `docs/long-term-memory/reports/` and retains stable `#curation-boundary` and `#research-body` anchors.
5. `.uai/long-term-memory.uai` deep-links every report rather than copying full bodies.
6. `/research/library/.../` reads curated Markdown through the first-party renderer and presents accessible HTML. The HTML layer is derived presentation; Markdown remains durable research authority.

The renderer does not make report claims current merely by displaying them. Report pages visibly label working-research and evidence boundaries.

## Research-reader presentation

`/research/library/` remains a derived HTML lens over the 49 curated Markdown reports. Reading-quality, citation/canonical-link copy tools, same-ID heading permalinks, and the capped “Concepts in this report” module remain in force. Reciprocal glossary → research discovery continues to use the same exact configured term/alias detector. Related-report and glossary/research bridges are navigation aids only; they do not create scholarly citation, endorsement, policy agreement, or semantic-equivalence claims, and they do not modify durable report bytes.

## Research topic routing

Six topic hubs under `/research/topic/.../` are generated from the existing `topic` values in the report manifest. Each hub lists exactly its manifest-assigned reports, aggregates up to ten exact-match glossary concepts from those report bodies, and links only to already-implemented public context selected for that topic. Topic/concept relationships are presentation-only discovery metadata and are not injected into structured data as curated semantic assertions. `/research/`, `/research/library/`, and individual report readers cross-link these hubs without adding new top-navigation items.


## Research methodology and verification boundary

`/research/methodology/` explains the repository research workflow using existing curation policy, manifest, source-map, status, and accepted decision evidence. It distinguishes source SHA-256 from curated SHA-256 as byte-identity records; neither is treated as proof of factual correctness, currentness, authorship, legal/scientific authority, deployment, or autonomous provenance. The page also documents that manifest topics, exact glossary matches, and related-report heuristics are navigation aids rather than semantic authority. Time-sensitive external claims require fresh primary evidence before current public reliance.

## Glossary architecture

`/glossary/` is a first-party concepts registry with 20 defined terms. Term pages include direct, plain-language and technical definitions; explicit implications/non-implications; related concepts; `DefinedTerm` structured data; and a capped “Research using this concept” module derived from exact configured occurrences in curated report bodies. The glossary index shows per-term corpus coverage counts. These counts are discovery metadata, not semantic endorsement. Glossary taxonomy keeps intelligence, consciousness, sentience, personhood, legal personhood, moral patienthood, and citizenship distinct.

## Rights / personhood / citizenship architecture

These routes are public research/exploration surfaces, not legal-status declarations. Each page exposes a direct answer, research question, proposal directions, unresolved questions, related terminology, and curated research links. Pages intentionally avoid presenting report proposals as established rights, current citizenship, or installed governance infrastructure.

## Identity continuity explainer

`/identity/continuity/` visualizes the accepted separation `Identity ≠ Key ≠ Model ≠ Runtime ≠ Server` and ten continuity events. It explains continuity evidence and single-signal limits without installing any cryptographic identity protocol.

## Transparency Center

`/transparency/` separates locally inspectable repository evidence from documentary claims and external state. Subroutes cover release integrity, provenance, stewardship, human/machine boundaries, and release history. `/transparency/integrity/` reads the static root `release-manifest.json`; it does not recompute package hashes during public requests. The center does not claim cryptographic machine-execution provenance that the repository cannot independently prove.

## Search / AEO / GEO surface

The site uses the same visible content for human and machine readers: direct answers, semantic headings, canonical URLs, breadcrumbs, matching structured data, descriptive first-party media, and sitemap discovery. Structured data is supplementary description of visible page content; it is not treated as evidence that a search platform will display a special result.

## Failure paths and boundaries

- a PHP syntax/runtime failure can take down a route family;
- bad canonical-origin configuration can produce external indexing ambiguity even when local pages render;
- report-manifest/path drift can break the public research reader;
- malformed Markdown can degrade presentation but must not escape HTML sanitization boundaries;
- missing CSS/JS degrades presentation/interaction but core semantic content remains server-rendered;
- root-relative links assume web-root deployment;
- public rights/civic/transparency pages do not implement the researched institutional systems they discuss;
- production host behavior and live external state remain verify-before-use facts.

## Research-only architecture

Reports propose stronger cryptographic identity, rights, civic, economic, democratic, and provenance systems. Inclusion in `docs/` or public research pages does not install those systems. Future implementation requires an accepted decision, current evidence review, compatibility with hard dependency/authority constraints, and focused tests/proof.


## Research references and source discovery

`/research/references/` is a derived local-only index over URL tokens that already occur in the 49 curated Markdown reports. `includes/research-references.php` extracts HTTP/HTTPS destinations, removes Markdown backslash escapes before punctuation, lowercases hosts, removes only default HTTP/HTTPS ports, excludes internal MachineIntelligences.org absolute URLs, de-duplicates usable URLs, groups them by normalized domain, and records canonical report backlinks plus occurrence counts.

The renderer never fetches external URLs. Reference occurrence is therefore evidence only that a URL is present in the curated corpus; it is not evidence of reachability, currentness, correctness, authority, endorsement, peer review, or support for a nearby claim. Fresh primary-source verification remains separate when current external state matters.


## Research Navigator

`/research/navigator/` is a server-rendered, first-party discovery surface over metadata that already has accepted repository owners. Report matching uses only report-manifest title, curated summary, and topic label fields; topic matching uses accepted manifest topic labels; glossary matching uses accepted term titles and direct definitions; reference-domain matching uses only normalized domain names from the local reference extractor. It does not build a full-report-body search index, infer semantic relationships, score sources, or fetch external destinations.

Result types remain visibly separated. Domain results route to deterministic fragments on the existing canonical `/research/references/` page. Native JavaScript progressively adds multi-token filtering, result-type controls, shareable `q`/`type` URL state, clear/reset, live counts, and `/` search focus, but all current Navigator entries remain server-rendered and usable without JavaScript. Query state never changes canonical/OG/JSON-LD page identity. The large domain group uses compact markup plus `content-visibility` hints to reduce transfer/renderer cost without removing any domain from no-JavaScript HTML.

## Research accessibility and print presentation

v0.18.0 keeps research content server-rendered while tightening interaction and output semantics. Dynamic result surfaces use explicit status semantics, report evidence/citation cards have accessible group labels, the Navigator shortcut avoids already-interactive controls, external reference links preserve normal browser navigation, and reduced-motion preference suppresses report-progress work plus nonessential research-surface transitions.

Report readers and Research Methodology now have first-party print rules. Report print output preserves title/summary, report metadata, truth boundary, source attachment identity, source/curated SHA-256 values, substantive article content, semantic tables, code, and useful destinations while removing site navigation, TOC/copy/navigation chrome, progress decoration, and derived related/concept modules. Methodology print output retains substantive workflow and evidence-boundary material while removing web-only controls. This is a presentation contract only; it does not change durable report bytes, manifest authority, glossary definitions, or evidence status.


## v0.19.0 shared accessibility and responsive layer

The shared shell now provides a no-JavaScript mobile navigation fallback, synchronized menu state naming, and keyboard focus return for closed menu/disclosure interactions. Share/Respect media expose stronger names/status descriptions; the silent social reel includes a text description and does not autoplay. Identity and Transparency visuals use semantic list/order structures. Shared CSS extends target-size, overflow, reduced-motion, and forced-color defenses outside research pages while retaining the v0.18.0 research print contract unchanged.

## v0.20.0 first-party media delivery layer

The public media layer now separates accepted full-resolution campaign originals from routine delivery derivatives. The homepage hero exposes 480/720/1200/1672 WebP candidates while retaining the full-resolution PNG for social/structured metadata and fallback. Six Respect essays use 480/720/1080 WebP display candidates and keep the original PNG behind the explicit full-resolution artwork link. Terminology, Identity, Stewardship, and Research contextual campaign blocks use bounded WebP previews; Share image cards use 480 plus 720/768 preview candidates and preserve full-resolution downloads.

The homepage hero remains the only campaign image explicitly eager/high-priority. Other campaign images are lazy-loaded with intrinsic dimensions. The first-party MP4 remains non-autoplaying with native controls, metadata preload, fallback text, and the v0.19.0 visible description; its visible poster is a smaller 960×540 derivative while the larger discovery poster remains available for structured metadata.

Responsive derivatives are static repository assets, not new content authority and not a runtime dependency. No CDN, remote optimizer, third-party player, analytics, tracking, database, crawler, or external font is introduced. Browser-selected candidates, Core Web Vitals, cache behavior, and production network waterfalls remain external/browser evidence rather than repository-proven facts.

## v0.22.0 HTTP delivery and cache-readiness layer

Shared mutable CSS and JavaScript use one release-aware query key derived from `SITE_RELEASE`; page canonical identity remains clean and query-free. The root `.htaccess` retains directory-index/anti-listing behavior and now contains only optional-module-guarded cache/compression directives: text-like responses may be deflated, CSS/JS use a seven-day cache-readiness window, and non-fingerprinted first-party image/video assets use a bounded thirty-day window. Already-compressed PNG/JPEG/WebP/ICO/MP4 formats are not added to the deflate type list.

This is repository configuration, not proof of live Apache module availability or production caching. `docs/long-term-memory/performance/v0.22.0-local-performance-budget.json` records deterministic local response/file bytes and simulated gzip sizes for representative routes/assets. In v0.22.0 the fully server-rendered `/research/references/` inventory was the known budget outlier; that release deliberately preserved all extracted references and deferred representational compaction to the next bounded pass.


## v0.23.0 Research References compact evidence layer

`/research/references/` retains the complete local-only extraction but de-duplicates repeated presentation. `includes/research-references.php` now assigns deterministic compact report keys from report slugs and provides bounded display labels for long URLs. The page renders each full report title/canonical reader URL once in a visible legend, uses compact report-key backlinks with shared accessible descriptions, keeps the complete normalized external URL in each `href`, and preserves all stable domain fragment IDs.

Native search reads visible row text, complete external `href` values, and full report titles recovered from the one-time legend, so shortening visible URL labels does not remove deep path/query discovery or report-title search. All URLs, report mappings, domain groups, and backlinks remain server-rendered for no-JavaScript access. The representation reduces local raw HTML from 2,343,653 to 772,144 bytes while preserving 3,932 occurrences, 1,900 unique URLs, 1,070 domains, and 2,014 URL-to-report relationships. This is repository performance evidence, not proof of production transfer behavior.


## v0.24.0 report-local reference traceability

`includes/research-library.php` now exposes one shared collision-safe Markdown heading-ID helper used by both the renderer and local reference-context derivation. `includes/research-references.php` can derive report-local normalized URL occurrence counts plus nearest-preceding rendered section context without fetching external sources or changing Markdown. Every manifest-backed report reader renders a collapsed, server-side References-in-this-report disclosure with a one-time section-key legend, exact external destinations, stable global-domain backlinks, and explicit evidence-boundary language. The global References index remains the canonical cross-report source-discovery surface and keeps its v0.23.0 compact representation.


## v0.25.0 static release-integrity layer

The root `release-manifest.json` is a packaging-time artifact, not a runtime hash service. It deterministically lists every regular file in the root-deployable release except itself, sorted by repository-relative path, with byte size and SHA-256. Its summary contains the covered file count and covered byte total. The manifest explicitly records self-exclusion because including its own final digest would be recursively undefined.

`/transparency/integrity/` reads only that static JSON artifact and presents its release identity, algorithm, aggregate counts, exclusions, local recomputation instructions, and evidence boundary. Package-file equality is narrower than deployment provenance: matching hashes do not prove live-host state, authorship, autonomous execution, external factual correctness, source authority, legal identity, or ownership. The handoff ZIP exists outside the web-root package and is therefore verified separately rather than silently folded into the manifest contract.


## v0.26.0 error handling and security-header readiness

- Apache `ErrorDocument 404 /404/` targets a first-party utility response that explicitly returns HTTP 404.
- `/404/` is not a canonical public route: it is absent from `sitemap.xml`, emits `noindex,follow`, emits no canonical link, and emits no JSON-LD page identity.
- The recovery response links only to known first-party recovery destinations: Home, Research Navigator, Glossary, Respect, Transparency, and Sitemap.
- `.htaccess` disables MultiViews to reduce extension/content-negotiation ambiguity around the clean directory-route architecture.
- When `mod_headers` is available, Apache is instructed to emit `X-Content-Type-Options: nosniff`, `Referrer-Policy: strict-origin-when-cross-origin`, and `X-Frame-Options: SAMEORIGIN`. The directives are hosting-readiness configuration, not proof that production enables the module or serves those headers.
- No Content Security Policy is introduced in this release because the full inline JSON-LD/style/media compatibility contract was not promoted to an accepted CSP policy.
- The static release-manifest model remains package-time evidence; it is regenerated only after covered files are finalized.
