The first day: Z Route Academy went from an Astro starter template to a launched site in ten build phases.
Foundation (Phases 01-06)
- Information architecture, navigation, layouts, and site metadata for the whole public knowledge base.
- A field-guide design system: verification-status badges, card and callout components, and a distinct dark theme for the private alliance area.
- The core content collections — guides, heroes, events, glossary — with schema validation. Every
entry started as an honest
NEEDS_VERIFICATIONstub rather than invented content, per this site’s accuracy rule. - A build-time search index with vanilla-JS scored client-side search — no hosted search service.
- Discord OAuth login (PKCE + CSRF state) with D1-backed sessions, authorization checks, and the private NexS Command Center behind auth-gated routes. The site switched to hybrid rendering so the private area runs per-request while the public knowledge base stays static.
Interactive tools, and the TOZ → NexS rename
The HQ/Base Upgrade Planner, Resource Calculator, Shard Calculator, and Command Calculator arrived as Phase 07 — each one honestly reporting “no data yet” rather than guessing where real numbers weren’t available yet.
The alliance itself was renamed [TOZ] TerminateOnSite → [NexS] NeXuS the same day, done cleanly
since nothing was in production yet: routes moved from /toz/* to /nexs/*, and every matching
code identifier (TozPageLayout, isTozFamily, TOZ_FAMILY_ALLIANCES, and so on) was renamed to
match.
A tactical redesign
The site’s visual language shifted from a light “field guide” look to a dark, tactical, post-apocalyptic-survival aesthetic — new color tokens, a self-hosted display font for headings, and an intensified theme for the NexS Command Center. The homepage hero picked up HUD-style corner brackets and a large low-opacity typographic “Z,” built entirely in CSS with no image assets.
A real correction workflow
Rather than an open-edit wiki, Phase 08 added a curated correction queue: a public /contribute/
form (linked from every article’s “Suggest a Correction” button, pre-filled with the page you were
reading), a hidden honeypot and rate limiting for abuse protection, and a private review screen
gated to R4+ alliance officers. Accepting a submission never touches content files automatically —
a person still has to make the edit.
SEO, security, accessibility, analytics
Phase 09 covered a lot of ground in one pass: JSON-LD structured data, a dynamic robots.txt that
can’t drift out of sync with the sitemap, noindex on every private route as a third independent
layer of protection, a missing font preload fixed, tuned cache headers, an ARIA anti-pattern fixed
in the mobile nav, all 14 database queries audited as fully parameterized, added
Strict-Transport-Security and Permissions-Policy headers, and cookie-free, PII-free analytics
via Cloudflare’s own Analytics Engine. The production domain (zroute.dev) was registered and wired
up the same day.
Launch audit
Phase 10 closed out the day with a final audit: custom 404/500 pages, a mobile logout-button fix, and a re-verification of the public/private content separation, search accuracy, database migration state, and security headers. No launch blockers were found.
An R5-gated admin page for managing member alliance/rank/cabinet assignments shipped the same day, closing out launch day’s work.