Public pages
Choose which pages anyone can open, for websites, forms and portals.
Built on Caddy
Plans: Every plan, including the free app
What you get
- Public pages chosen route by route
- Everything else behind sign-in
- Public forms protected from bots
- Form posts from other websites refused
- Signed-in people recognised on public pages
- Your own response headers, such as a Content Security Policy
How it works
Every route of an app is private until it is listed under routes.public in whisk.yaml. Caddy, the open-source web server in front of every app, checks each request before it reaches the app. A visitor to a private page is sent to sign in.
A public page reaches the app with the visitor marked as anonymous. If someone is signed in, the app also gets who they are, so one page can show a public view and a signed-in view.
Forms that strangers fill in, such as a quote request, go under routes.challenge. A post to them must carry a solved bot check from Altcha, which runs without any third-party service. Posts sent from other websites are refused, so forms need no extra token.
Example
A packaging wholesaler runs its company website and quote request form from one app. The home page and product pages are public, and the quote form asks each visitor to pass a bot check. The pages where staff handle quotes need sign-in.
For your coding agent
routes: public: ["/", "/products/**", "/quote", "/health"] challenge: ["/quote"]
Public pages can also be answered from the edge cache with a Cache-Control header. Every field is in the whisk.yaml reference.