Every route this repository serves, with the file behind it and the caller allowed to reach it. The list is complete rather than curated: a route that is not here does not exist. Only the routes worth explaining carry a note.
73 routes · 9 actors
| Method | Path | Actor | File |
|---|---|---|---|
| GET | / | public | app/routes/_marketing/index.tsx |
| GET | /about | public | app/routes/_marketing/about.tsx |
| GET | /privacy | public | app/routes/_marketing/privacy.tsx |
| GET | /support | public | app/routes/_marketing/support.tsx |
| GET | /tos | public | app/routes/_marketing/tos.tsx |
| GET | /robots.txt | public | app/routes/_seo/robots[.]txt.ts |
| GET | /sitemap.xml | public | app/routes/_seo/sitemap[.]xml.ts |
Generated from the route manifest by @nasa-gcn/remix-seo; routes opt out with `handle.getSitemapEntries: () => null`, which is why auth and settings routes export that handle. | |||
| GET | /login | anonymous visitor | app/routes/_auth/login.tsx |
| POST | /login | anonymous visitor | app/routes/_auth/login.tsx |
Creates the Session row first, then handleNewSession decides: users with 2FA get the session id parked in en_verification and a redirect to /verify?type=2fa, everyone else gets en_session. | |||
| GET | /logout | public | app/routes/_auth/logout.tsx |
| POST | /logout | public | app/routes/_auth/logout.tsx |
| GET | /signup | anonymous visitor | app/routes/_auth/signup.tsx |
| POST | /signup | public | app/routes/_auth/signup.tsx |
Unlike the page, the action does not call requireAnonymous; it rejects an email that already has an account, emails a ten-minute onboarding code and redirects to /verify. | |||
| GET | /forgot-password | public | app/routes/_auth/forgot-password.tsx |
| POST | /forgot-password | public | app/routes/_auth/forgot-password.tsx |
Answers 'No user exists with this username or email' for unknown accounts, unlike the reset handler that deliberately hides it, and sits outside the strongest rate-limit tier although every valid request sends an email. | |||
| GET | /reset-password | anonymous visitor with verification cookie | app/routes/_auth/reset-password.tsx |
| POST | /reset-password | anonymous visitor with verification cookie | app/routes/_auth/reset-password.tsx |
| GET | /verify | public | app/routes/_auth/verify.tsx |
| POST | /verify | public | app/routes/_auth/verify.tsx |
The single endpoint behind onboarding, password reset, email change and 2FA login: it checks a TOTP code against the Verification row for the submitted type and target and dispatches to that flow's handler in verify.server.ts. | |||
| GET | /onboarding | anonymous visitor with verification cookie | app/routes/_auth/onboarding/index.tsx |
| POST | /onboarding | anonymous visitor with verification cookie | app/routes/_auth/onboarding/index.tsx |
| GET | /onboarding/:provider | anonymous visitor with verification cookie | app/routes/_auth/onboarding/$provider.tsx |
| POST | /onboarding/:provider | anonymous visitor with verification cookie | app/routes/_auth/onboarding/$provider.tsx |
| GET | /auth/:provider | public | app/routes/_auth/auth.$provider/index.ts |
| POST | /auth/:provider | public | app/routes/_auth/auth.$provider/index.ts |
Starts the OAuth redirect (github is the only provider); signed-in users post here from settings to link an account. With MOCK_ GitHub credentials it skips GitHub and redirects straight to the callback with a fake code. | |||
| GET | /auth/:provider/callback | public | app/routes/_auth/auth.$provider/callback.ts |
A GET that writes: it links a connection, signs in, or starts onboarding depending on whether the visitor is signed in and the GitHub account or email is already known, so it calls ensurePrimary() first. | |||
| GET | /webauthn/authentication | public | app/routes/_auth/webauthn/authentication.ts |
| POST | /webauthn/authentication | public | app/routes/_auth/webauthn/authentication.ts |
Passkey sign-in as JSON: the GET issues options and stores the challenge in a cookie, the POST verifies the signed response against the stored public key and passes the new session through handleNewSession, so 2FA still applies. | |||
| GET | /webauthn/registration | signed-in user | app/routes/_auth/webauthn/registration.ts |
| POST | /webauthn/registration | signed-in user | app/routes/_auth/webauthn/registration.ts |
| GET | /me | signed-in user | app/routes/me.tsx |
| GET | /users | public | app/routes/users/index.tsx |
User search runs prisma/sql/searchUsers.sql through TypedSQL: a LIKE match on username or name, ordered by each user's most recently updated note and capped at 50. | |||
| GET | /users/:username | public | app/routes/users/$username/index.tsx |
| GET | /users/:username/notes | public | app/routes/users/$username/notes/_layout.tsx |
| GET | /users/:username/notes/new | signed-in user | app/routes/users/$username/notes/new.tsx |
| POST | /users/:username/notes/new | signed-in user | app/routes/users/$username/notes/+shared/note-editor.server.tsx |
Shares its action with the edit route; a new note is always owned by the signed-in user, whatever `:username` is in the URL. | |||
| GET | /users/:username/notes/:noteId | public | app/routes/users/$username/notes/$noteId.tsx |
| POST | /users/:username/notes/:noteId | note owner or admin | app/routes/users/$username/notes/$noteId.tsx |
| GET | /users/:username/notes/:noteId/edit | note owner | app/routes/users/$username/notes/$noteId_.edit.tsx |
Loads the note filtered by `ownerId`, so the admin role's seeded `update:note:any` permission is never consulted — even though admins see the Edit button, because the toolbar renders whenever they can delete. | |||
| POST | /users/:username/notes/:noteId/edit | note owner | app/routes/users/$username/notes/+shared/note-editor.server.tsx |
| GET | /settings/profile | signed-in user | app/routes/settings/profile/index.tsx |
| POST | /settings/profile | signed-in user | app/routes/settings/profile/index.tsx |
One action with three intents chosen by the `intent` field: update-profile, sign-out-of-sessions and delete-data. | |||
| GET | /settings/profile/change-email | recently re-verified user | app/routes/settings/profile/change-email.tsx |
| POST | /settings/profile/change-email | signed-in user | app/routes/settings/profile/change-email.tsx |
Only the page's loader demands recent 2FA verification; the action checks for a session, rejects an email already in use and starts a change-email verification that completes through /verify. | |||
| GET | /settings/profile/connections | signed-in user | app/routes/settings/profile/connections.tsx |
| POST | /settings/profile/connections | signed-in user | app/routes/settings/profile/connections.tsx |
| GET | /settings/profile/passkeys | signed-in user | app/routes/settings/profile/passkeys.tsx |
| POST | /settings/profile/passkeys | signed-in user | app/routes/settings/profile/passkeys.tsx |
| GET | /settings/profile/password | signed-in user | app/routes/settings/profile/password.tsx |
| POST | /settings/profile/password | signed-in user | app/routes/settings/profile/password.tsx |
| GET | /settings/profile/password/create | signed-in user | app/routes/settings/profile/password_.create.tsx |
| POST | /settings/profile/password/create | signed-in user | app/routes/settings/profile/password_.create.tsx |
| GET | /settings/profile/photo | signed-in user | app/routes/settings/profile/photo.tsx |
| POST | /settings/profile/photo | signed-in user | app/routes/settings/profile/photo.tsx |
| GET | /settings/profile/two-factor | signed-in user | app/routes/settings/profile/two-factor/index.tsx |
| POST | /settings/profile/two-factor | signed-in user | app/routes/settings/profile/two-factor/index.tsx |
| GET | /settings/profile/two-factor/verify | signed-in user | app/routes/settings/profile/two-factor/verify.tsx |
| POST | /settings/profile/two-factor/verify | signed-in user | app/routes/settings/profile/two-factor/verify.tsx |
Confirms the code from the authenticator app and renames the pending `2fa-verify` Verification row to `2fa`, which is what turns two-factor on for every later login. | |||
| GET | /settings/profile/two-factor/disable | recently re-verified user | app/routes/settings/profile/two-factor/disable.tsx |
| POST | /settings/profile/two-factor/disable | recently re-verified user | app/routes/settings/profile/two-factor/disable.tsx |
| GET | /resources/images | public | app/routes/resources/images.tsx |
The openimg optimiser: `objectKey` fetches from Tigris with a signed request, `src` fetches an allowlisted URL or a local file, and resized results are cached on disk and served with a one-year immutable Cache-Control. | |||
| GET | /resources/healthcheck | public | app/routes/resources/healthcheck.tsx |
Polled by the http_check in fly.toml every 10 seconds: it runs SELECT 1 and a HEAD request to the app's own host, returning 500 if either fails. | |||
| POST | /resources/theme-switch | public | app/routes/resources/theme-switch.tsx |
| GET | /resources/download-user-data | signed-in user | app/routes/resources/download-user-data.tsx |
| GET | /admin/cache | admin | app/routes/admin/cache/index.tsx |
| POST | /admin/cache | admin | app/routes/admin/cache/index.tsx |
| GET | /admin/cache/lru/:cacheKey | admin | app/routes/admin/cache/lru.$cacheKey.ts |
| GET | /admin/cache/sqlite/:cacheKey | admin | app/routes/admin/cache/sqlite.$cacheKey.ts |
| POST | /admin/cache/sqlite | replica instance | app/routes/admin/cache/sqlite.server.ts |
Not for people: the action runs only on the primary and only for `Authorization: Bearer INTERNAL_COMMAND_TOKEN`, a value the Dockerfile generates per image; any other caller is redirected to an external video. | |||
| GET | /assets/* | public | server/index.ts |
Fingerprinted build output served by express.static with a one-year immutable cache and no fallthrough, so a missing asset is a 404 rather than a rendered page. | |||
| GET | /img/* | public | server/index.ts |
| GET | /favicons/* | public | server/index.ts |
Registered before express.static even though its comment assumes the opposite order, so it answers 404 for the Android icons that public/site.webmanifest references. | |||
| ANY | /* | public | app/routes/$.tsx |