internal/web/static/style.css:14, :21, :28 declare @font-face for /static/fonts/atkinson-*.woff2. The embedded directory contains those three files. internal/httpd/routes.go:46-48 register plex-sans.woff2, plex-mono-400.woff2 and plex-mono-500.woff2. Both names 404 on the live site:
curl -I https://gitbay.org/static/fonts/atkinson-next-roman.woff2 -> 404
curl -I https://gitbay.org/static/fonts/plex-sans.woff2 -> 404
Every visitor sees the system fallback stack. Nothing tests that the URLs the CSS asks for are the ones the router serves.
Remedy: one /static/fonts/{name} route with an allowlist built from the embedded directory, and a test that GETs every url() in the embedded CSS.
closed by commit e5973a00dd by cmc: web: serve the fonts the stylesheet asks for
2026-09-03 15:06 UTC