# ALAI Website (alai.no)

ALAI Holding AS main website — AI services company landing page

# Overview

# Overview

## Domain &amp; Infrastructure

- **Domain:** `alai.no`
- **Vercel Project:** `ucenje-deploy`
- **Local Repository:** `~/ALAI/web`
- **Remote Repository:** `https://github.com/johnatbasicas/alai-web.git`
- **Tech Stack:** Next.js 14, React, Tailwind CSS, Vercel

## Deploy Method

cc-api-server /bash → vercel --prod

## Quick Links

- [Live Site: alai.no](https://alai.no)

# Architecture

# Architecture

## Technology Stack

Next.js 14, React, Tailwind CSS, Vercel

## Infrastructure

*To be documented: hosting environment, dependencies, integrations*

## Deployment Pipeline

cc-api-server /bash → vercel --prod

## Dependencies

*To be documented: external services, APIs, databases*

# Deploy Runbook

# Deploy Runbook — alai.no

**Last updated:** 2026-04-15
**Status:** Production — VERIFIED

---

## Infrastructure

| Field | Value |
|-------|-------|
| **Live URL** | https://alai.no |
| **CDN** | Vercel (confirmed via response headers) |
| **Repo** | `~/ALAI/web` |
| **Hosting type** | Static (plain HTML/CSS/JS, no build step) |
| **Output dir** | `public/` (served directly by Vercel) |
| **Vercel project** | alai (linked via `~/ALAI/web/.vercel/`) |

> ⚠️ `~/projects/ALAI/landing` is a stale Next.js experiment with Firebase config — **NOT live, NOT deployed, ignore it.**

---

## Deploy Steps

```bash
cd ~/ALAI/web
git pull origin master
# make changes to public/
git add public/
git commit -m "feat: description"
vercel --prod
```

## Verify

```bash
curl -sI https://alai.no | grep -i "server\|vercel"
# Expected: server: Vercel
```

## Rollback

```bash
# List deployments
vercel ls

# Rollback to previous deployment URL
vercel rollback [deployment-url]
```

## Known Issues

- **2026-04-15**: `/ucenje/` subpage links used directory-style paths (`/ucenje/mladi/`) instead of `.html` files. Fixed in `public/ucenje/index.html` — deploy pending.
- Vercel token occasionally needs re-auth: `vercel login`

## What NOT to use

- ❌ Firebase (`~/projects/ALAI/landing`) — stale, not connected to alai.no
- ❌ `~/projects/ALAI/landing` — Next.js experiment, dead project

# Current State

# Current State

## What Works

- *To be documented*

## What Doesn't Work / Known Issues

- *To be documented*

## Open Tasks

*Link to Mission Control tasks related to this project*

## Last Verified

**Date:** 2026-04-15

**Status:** Initial documentation shell created

# Changelog

# Changelog

## 2026-04-15 — Documentation Shell Created

- Initial BookStack book structure created
- Overview, Architecture, Deploy Runbook, Current State pages added
- Task: `#7763` (DOD System: BookStack Shell per projekat)

---

*All significant deploys and changes should be logged here with date, description, and deploy ID.*

# ucenje v3 — aha math + pčele + interaktivan 6×19

# ucenje v3 — aha math + pčele + interaktivan 6×19

## Background

On **2026-04-22**, CEO Alem Basic provided feedback via Slack about the /ucenje section:

> Ne sviđa mi se kompletan UI/UX. Previše teksta ima za to što poučavamo. Trebamo promijeniti stil. Hoću animacije i slike na svim stvarima — ne samo tekst.

During the **2026-04-23** session, he clarified the scope:

- Convert /ucenje/matematika.html from text-heavy to visual, aha moment style
- Create new /ucenje/pcele.html page showcasing bees × 6×19 × honeycomb structural parallel
- Make 19-explorer interactive (114-cell grid with hover states, showing 6×19 structure)
- Add /ucenje hub tile for pcele.html
- Maintain respectful, scholarly tone (Islamic content — dignified, contemplative, precise)

Full v3 redesign deployed to production: [https://alai.no/ucenje/](https://alai.no/ucenje/)

## Changes Made

### MC Tasks

Five Mission Control tasks executed in sequence:

<table id="bkmrk-task-id-owner-title-"><thead><tr><th>Task ID</th><th>Owner</th><th>Title</th><th>Deliverable</th></tr></thead><tbody><tr><td>\#8931</td><td>datavera</td><td>Research: pčele × 6×19 × honeycomb conjecture</td><td>`/Users/makinja/system/context/quran/bees-6x19-parallel.md`</td></tr><tr><td>\#8932</td><td>proxima</td><td>Math aha copy: 3-lang bilingual</td><td>`~/ALAI/web/public/ucenje/content/math-aha-{bs,no,en}.md`</td></tr><tr><td>\#8933</td><td>vizu</td><td>matematika.html redesign + pcele.html new + 19-explorer interactive</td><td>Commits `cac230d` + `14b0be0` on `~/ALAI/web` master</td></tr><tr><td>\#8934</td><td>proveo</td><td>QA validation — all pages LIVE</td><td>36/36 PASS on alai.no — report: `/tmp/ucenje-v3-validation/report-LIVE.json`</td></tr><tr><td>\#9035</td><td>flowforge</td><td>CF Pages deploy fix (manual wrangler)</td><td>DEPLOY-MAP.md created, commit `a1ce178`</td></tr></tbody></table>

### New Files

- `public/ucenje/matematika.html` — redesigned: 13 visual cards (3 hero + 10 content), minimal text, bilingual aha-style copy
- `public/ucenje/pcele.html` — NEW: bees × 6×19 × honeycomb conjecture parallel, SVG hex animation, 19-TET sonification tie-in
- `public/ucenje/content/math-aha-{bs,no,en}.md` — bilingual content chunks for matematika.html cards
- `public/ucenje/19-explorer/` — interactive 114-cell grid with hover states, showing 6×19 structure, mobile horizontal scroll
- `DEPLOY-MAP.md` — deployment verification checklist (part of ZAKON PI2 compliance)

### Design Decisions

**Vizu team** (Brad Frost + Lea Verou) made the following trade-offs:

1. **Arabic RTL inline spans** — Arabic text rendered with `dir=rtl lang=ar` inside LTR paragraph flow; avoids full page RTL (preserves BS/NO/EN left-to-right structure)
2. **SVG hexagon animation** on pcele.html — subtle scaling pulse (1.0 → 1.05) to draw eye to honeycomb structure without being distracting
3. **Mobile horizontal scroll for 6×19 grid** — 19 columns exceed mobile viewport; horizontal scroll preserves grid integrity (alternative: responsive collapse loses visual pattern)
4. **13-card layout for matematika.html** — 3 large hero cards (number 19, grid, prime factors) + 10 smaller aha cards; hero size = visual hierarchy
5. **Bilingual inline toggle** — BS primary, NO/EN via lang switcher; kept single-page experience vs. separate /bs/, /no/, /en/ routes

## QA Evidence

**Proveo team** (Angie Jones) executed full validation on LIVE production ([https://alai.no/ucenje/](https://alai.no/ucenje/)):

- **36/36 PASS** — all test cases passed
- **Report:** `/tmp/ucenje-v3-validation/report-LIVE.json`
- **Screenshots:** `/tmp/ucenje-v3-validation/*-LIVE.png` (8 files: hub, matematika desktop/mobile, pcele desktop/mobile, 19-explorer desktop/mobile, navigator)

No regressions detected. All links functional, all language toggles working, all interactive elements responsive.

## Deploy Process

**FlowForge team** (Kelsey Hightower) identified systemic webhook issue (#9050 — GH Actions → CF Pages webhook not firing). Temporary fix:

1. Manual `wrangler pages deploy` from local machine
2. Created `DEPLOY-MAP.md` in repo root (ZAKON PI2 compliance)
3. Tracked as MC #9050 for permanent GH Actions backup workflow

Reference commit: `a1ce178`

## Credit Chain

Per rule `~/system/rules/no-agent-persona-as-author.md`, public-facing credits MUST NOT include agent persona names (Brad Frost, Lea Verou, etc.). Correct attribution:

- **Primary research:** dr. Rashad Khalifa (1974) — first mathematical documentation of number 19 in Quran
- **Popularization:** Ahmed Deedat (IPCI, 1979) — book *Al-Qur'an: The Ultimate Miracle*
- **Original work:** ALAI, 2026 — 6×19 honeycomb parallel, 19-TET sonification, interactive explorer

Every /ucenje page footer credits Khalifa + Deedat in Acknowledgment section. Byline = **ALAI, 2026**.

## Live URLs

- Hub: [https://alai.no/ucenje/](https://alai.no/ucenje/)
- Matematika: [https://alai.no/ucenje/matematika.html](https://alai.no/ucenje/matematika.html)
- Pčele: [https://alai.no/ucenje/pcele.html](https://alai.no/ucenje/pcele.html)
- 19-Explorer: [https://alai.no/ucenje/19-explorer/](https://alai.no/ucenje/19-explorer/)

## Related Documentation

- **Bees × 6×19 research:** [Research: Pčele × 6×19 × Honeycomb Conjecture](https://docs.basicconsulting.no/books/quran-research-computational-analysis/page/pcele-619-honeycomb-conjecture-strukturalna-paralela) (this BookStack)
- **Memory entry:** `/Users/makinja/.claude/projects/-Users-makinja/memory/project_alai_ucenje_quran_19.md` (local filesystem)
- **Source repo:** `~/ALAI/web` (master branch)

---

*Documented by Skillforge, 2026-04-24. CEO feedback session 2026-04-22 + 2026-04-23.*

# clients.alai.no — Hosted Proposal Page

# clients.alai.no — Hosted Proposal Page

**Type:** Vercel static site
**Target URL:** https://clients.alai.no
**Source:** `~/business/ALAI-Holding-AS/products/clients-alai-no/`
**MC task:** #9410

## Purpose
Minimal, single-purpose hosted proposal landing page. One CTA hands off to ALAI Documenso for signing (`https://sign.alai.no/signin`). No framework, no JS, no build step — hand-written HTML5 + vanilla CSS, deployed via `vercel --prod`.

## Design
- ALAI dark theme: `--bg:#09090b`, `--surface:#111113`, `--accent:#00E5A0`, `color-scheme: dark`.
- Mobile-first: single-column layout under 720px, 3-column feature grid + horizontal CTA row above 720px (`@media (min-width: 720px)`).
- Exactly one interactive element on the page: the CTA anchor.
- `robots.txt` = `Disallow: /` (private proposal link, not for search indexing).

## Verified state (2026-08-08)
- `curl -sI https://clients.alai.no` → `HTTP/2 200`, served by Vercel, `content-length: 6885` (byte-for-byte match with local `index.html`).
- Live HTML has exactly one `<a>` tag → `href="https://sign.alai.no/signin"`.
- `https://sign.alai.no/signin` → `HTTP 200` (Documenso reachable, not a dead link).
- Vercel project linked: `prj_2Qzvszx7qg4pnzsRf3ZqhddUMaam`.
- `robots.txt` served correctly at `/robots.txt`.

## Known gap
The `products/clients-alai-no/` directory is **untracked** in the `ALAI-Holding-AS` git repo — it was deployed straight via `vercel --prod`, not through git-triggered CI. Non-blocking (the live deploy works), but a follow-up commit would close the hygiene gap. Not done in this pass because the parent checkout was mid-way on an unrelated feature branch (`feat/oauth-metrics-reader-103888`).

## Local verification
```bash
cd ~/business/ALAI-Holding-AS/products/clients-alai-no
python3 -m http.server 8765
curl -s http://localhost:8765 | grep -c "Proceed to secure signing"
```

## Deploy
```bash
vercel --prod
vercel domains add clients.alai.no
```

# Security Sweep — Public Repository & alai.no Hardening (MC #107285)

# Security Sweep — Public Repository & alai.no Hardening (MC #107285)

**Date:** 2026-08-16  
**Scope:** `johnatbasicas/alai-web`, `https://alai.no`, and `https://ucenje.alai.no`  
**Production commit:** `620dd3af082952b7dbded28a4c5b4685b5445366`  
**Pull request:** `johnatbasicas/alai-web#2`

## Trigger

The source repository was public and exposed tracked `CLAUDE.md` and `.claude/**` files. A full sweep was ordered to identify and remove repository, deployment, secret-handling, browser, and production exposure risks.

## Confirmed findings

1. Public GitHub access exposed agent metadata and internal operational instructions.
2. A stale `index.html.bak` file was publicly readable on `alai.no`.
3. A hidden internal `.credits.md` file was publicly readable on `ucenje.alai.no`.
4. Deprecated Vercel state contained expired OIDC tokens and duplicate local backups.
5. A legacy unused mail dependency had high-severity advisories.
6. GitHub Actions used mutable action tags; repository secret scanning and branch protection were unavailable or disabled.
7. Pages lacked a true 404 response and a complete Content Security Policy.
8. The contact proxy lacked bounded streaming input, complete validation, honeypot handling, safe upstream errors, and dynamic-response security headers.
9. The GitHub Cloudflare deploy token was stale, causing repeated authentication failures.
10. Wrangler debug logs contained local proxy shared-secret material and were too broadly readable.

## Remediation completed

### Repository and source

- Changed the GitHub repository to **private**; anonymous raw access now returns 404.
- Removed tracked `CLAUDE.md`, `.claude/**`, obsolete credential-setup instructions, and legacy Vercel/mail runtime files.
- Removed expired Vercel token files, deprecated Vercel state/backups, vulnerable local dependencies, and ignored HTML backups.
- Moved legitimate non-runtime documentation and verification sources outside deployable asset roots.
- Removed an unrelated Azure DevOps remote from the local web repository.

### Cloudflare Pages

- Added `.assetsignore` protection to both Pages roots.
- Added deterministic public-asset preflight validation and bypass regression tests.
- Added real `404.html` responses to both sites.
- Added CSP, HSTS, `nosniff`, clickjacking, permissions, referrer, and cross-origin headers.
- Removed Google-hosted font and analytics runtime dependencies instead of weakening CSP.
- Kept `ucenje` static-only by isolating its Wrangler working directory.
- Added edge tombstone redirects for the two stale cached sensitive paths; requests now resolve to 404.

### Contact endpoint

- Enforced JSON content type and an 8 KiB streaming body limit.
- Added strict name/email/message validation and conservative email grammar.
- Activated the existing honeypot.
- Restricted browser origins and unsupported methods.
- Added a 10-second upstream timeout and generic upstream failure responses.
- Added `no-store` and complete security headers to dynamic responses.

### CI and credentials

- Pinned GitHub Actions to immutable commit SHAs.
- Added Gitleaks, asset checks, Python regression tests, contact-function tests, and Dependabot.
- Restricted Actions to selected actions with mandatory SHA pinning and read-only defaults.
- Restored the valid scoped Cloudflare Pages token from the approved vault and updated GitHub Secrets without exposing the token.
- Verified canonical CI deployment of both Pages projects.
- Restricted Wrangler configuration/evidence permissions and removed debug logs containing proxy secrets.

## Verification

- Production Playwright gate: **21/21 PASS**.
- Browser console errors: **0**.
- Gitleaks current tree/history: **0 findings**.
- Semgrep OWASP/JavaScript: **0 findings**.
- Open Dependabot alerts: **0**.
- Canonical GitHub Actions deployment: **SUCCESS**.
- Sensitive live paths: **404 after edge routing**.
- Repository visibility: **PRIVATE**.

## Evidence

- `/Users/makinja/system/evidence/107285/final-security-sweep-report.json`
- `/Users/makinja/system/evidence/107285/browser-verification.json`
- `/Users/makinja/system/evidence/alai-web-security-sweep-20260816/FINAL-REPORT.md`

Evidence directories are restricted to user-only access. No credential values are recorded in this page or its evidence summaries.

## Residual low risks

1. GitHub branch protection for a private repository requires a paid plan. Compensating controls are enabled: private visibility, selected SHA-pinned Actions, read-only workflow permissions, Gitleaks CI, web commit signoff, and merged-branch deletion.
2. DNSSEC and CAA remain separate registrar/certificate-issuer changes and require a dedicated controlled rollout.
3. The edge tombstone rules should remain until the old one-week cache lifetime has fully elapsed; then revalidate direct paths before considering rule removal.

## Closure

Technical remediation and production verification are complete. This page is the task-specific BookStack record for MC #107285.