During the nginx outage the proxy URLs briefly served the landing page
WITH cacheable headers; browsers cached that HTML for the proxy URLs and
kept reading it after the origin recovered (satellites 'no satellites',
empty aircraft). no-store on every feed fetch means the browser cache can
never serve (or store) a poisoned body for data endpoints again. The
proxies are no-store server-side anyway — this closes the outage-window
loophole.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Three new layers from the OSINT4ALL directory triage:
- jamcams (registry): ~800 live London traffic cameras via TfL open API
(CORS-open, keyless). Click a cam dot -> live snapshot in the InfoBox,
5-min cache-busted refresh. New collapsed 'Regional - London' category.
- inciweb (registry): named US wildfire incidents from InciWeb RSS. New
spec.parse hook in the geojson-layer factory lets XML feeds supply their
own parser; coordinates regex'd out of DMS text in <description>.
- radio (bespoke): ~12k live radio stations from Radio Garden pinned to
their cities (PointPrimitiveCollection). Click -> station list + live
audio player (audio streams direct; JSON via new allowlisted serve.py
proxy/rg/ with 12h/1h caches, SSRF-tested). Keeps playing while you pan.
Deploy note: prod nginx needs a location for /godsigh/proxy/rg/ before
the radio layer works live (mirror of serve.py RG_PATH_RE allowlist).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>