Public pages

Choose which pages anyone can open, for websites, forms and portals.

Built on Caddy

Plans: Every plan, including the free app

What you get

  • Public pages chosen route by route
  • Everything else behind sign-in
  • Public forms protected from bots
  • Form posts from other websites refused
  • Signed-in people recognised on public pages
  • Your own response headers, such as a Content Security Policy

How it works

Every route of an app is private until it is listed under routes.public in whisk.yaml. Caddy, the open-source web server in front of every app, checks each request before it reaches the app. A visitor to a private page is sent to sign in.

A public page reaches the app with the visitor marked as anonymous. If someone is signed in, the app also gets who they are, so one page can show a public view and a signed-in view.

Forms that strangers fill in, such as a quote request, go under routes.challenge. A post to them must carry a solved bot check from Altcha, which runs without any third-party service. Posts sent from other websites are refused, so forms need no extra token.

Example

A packaging wholesaler runs its company website and quote request form from one app. The home page and product pages are public, and the quote form asks each visitor to pass a bot check. The pages where staff handle quotes need sign-in.

For your coding agent

routes:
  public: ["/", "/products/**", "/quote", "/health"]
  challenge: ["/quote"]

Public pages can also be answered from the edge cache with a Cache-Control header. Every field is in the whisk.yaml reference.

Read more

All features