OPENASS / LINK — PROJECT WEBSITE

Static project website for https://openass.wolperdinger.at.
Includes locally hosted 3D viewer, product renders, documentation,
source browser, searchable downloads and SHA-256 manifests.

Build from this project's hardware-box directory:

python3 -m venv /tmp/openass-site-tools
/tmp/openass-site-tools/bin/python -m pip install -r project-site/requirements-build.txt
/tmp/openass-site-tools/bin/python project-site/build_downloads.py
/tmp/openass-site-tools/bin/python project-site/build_site.py

The result is project-site/public/. Serve that directory with a static
HTTP server. No API key, database, Node runtime, hardware agent or
operator endpoint is required on the public web server.

Preview:
python3 -m http.server 4199 --directory project-site/public --bind 127.0.0.1

The complete/source ZIPs include the website sources. After changing
those sources, rebuild downloads first and the static site second.
The source templates contain markers replaced with actual metadata.

Model Viewer 4.3.1 is vendored under assets/vendor. See
THIRD_PARTY_NOTICES.txt and model-viewer.LICENSE.
Project artwork comes from design/v2/renders. Documentation is built
from the original hardware-box project files; local links are rewritten.

Deployment: separate Nginx vhost, dedicated static release directory,
current symlink, own TLS certificate. Do not serve .env, runtime logs,
venvs, build directories or the live Pi operator application publicly.
Source-browser copies have a .txt suffix and are inert text files.

Every source/asset and the generated public directory pass privacy_check.py.
The check also decompresses Blender files and reads ZIP payloads. Export stops
on personal home paths, the current local user identifier, known credential
signatures, or PNG text/EXIF metadata. Python 3.14 provides zstd in its standard
library; older supported Python versions use zstandard from requirements-build.
Diagnostics name only the file and category, never the matching value.
Run manually: python project-site/privacy_check.py project-site/public
Regression checks: python -m unittest discover -s project-site -p test_privacy_check.py

Blender export scripts use design/public_export.py to clear editor histories,
avoid private absolute paths in saved data and disable invisible PNG stamps.
The website builder recreates only its generated public/ directory so stale
raw/source exports cannot remain after the release allowlist changes.
