Dan Bednarski

pricklypears

Personal site running on Cloudflare Workers. Pure HTML+CSS, no JavaScript (enforced via CSP script-src 'none').

Live at https://112358132134.xyz/ – it is the homepage of that zone. The sibling paths /books/ and /stream/ are served by a different worker (books-112358132134, in ~/Docs/Books/kaq), and the HLS playlist and segments under /stream/ bypass Workers entirely and go to MediaMTX over a tunnel. That is why wrangler.toml lists exact routes instead of a 112358132134.xyz/* wildcard: a wildcard would swallow the video path and the root assets (/manifest.json, /beard-180.png) that the origin serves.

Deploy

npx wrangler deploy

The worker and its KV namespace live in dan.j.bednarski@gmail.com’s Cloudflare account, which owns the 112358132134.xyz zone. The site was previously deployed at p.ricklypears.workers.dev in a second account; see scripts/old-url-redirect/ for the redirect that retires that URL.

UPLOAD_TOKEN is a wrangler secret, not in this repo:

security find-generic-password -s journal-upload-token -a "$USER" -w \
  | npx wrangler secret put UPLOAD_TOKEN

How it works

The worker serves a fake terminal UI at /. Commands are submitted as GET params to /run (/run?cmd=who) and the server returns a full HTML page with the output. No client-side JS runs at all – the typewriter animation is pure CSS (@keyframes + steps()).

Commands go to /run rather than /?cmd= because Cloudflare matches route patterns against the entire URL including the query string and rejects a ? inside a pattern, so 112358132134.xyz/ alone never matches /?cmd=ls. The wildcard route 112358132134.xyz/run* does, without affecting any other path.

ls lists books/ and stream/ alongside the files, and cd <dir> redirects to them, so the sibling sites stay reachable from the homepage.

journal.enc is an encrypted Day One export (Argon2id + AES-256-GCM) pushed to /journal every 120s by the com.pears.journal-upload launchd job; gpg --decrypt journal.enc in the terminal decrypts it server-side. It is the only thing in the KV namespace (binding JOURNAL).

/room is pears’ office, top down: the sigil links to it and cd room walks there. The sprites in public/room/ are the pixel art from the old Pokeroom, recovered from git history (commit 4ddb8b37^). Today it is a static picture - furniture and both characters are laid out in CSS, so script-src 'none' still holds. Walking around, Mimikyu following, and interacting with the bookshelf, desk and chess set is the next step, and is the one thing here that will need a script: when it lands, /room gets script-src 'self' and nothing else does. The DOM is the layout data that script will read (element rects), so there is no second copy of the room to keep in sync.

The guestbook was removed on 2026-08-25. Its posts key is still in KV and holds visitor IPs and user-agents; archive it, then delete it.

Worker source is src/lib.rs (routing and commands) and src/template.rs (page shell).