guide
tit.server.routes.guide ¶
/api/guide/* — the fixed, packaged guide scene (plan R4).
The shape mirrors /api/scene/* on purpose, minus everything that made the
scene routes project routes: there is no subject parameter, no cache
state, no 202, no build. Every answer here is a read of a file that shipped
with the installation (:mod:tit.scene.guide), so the pane paints on a
machine with no project bound, no head model built, and no subject selected.
Three rules, each with the failure it prevents:
- No client string ever reaches the filesystem.
part,atlasandnetare checked against the packaged manifest's own ids before anything is opened, and the manifest's relative paths are resolved back inside the package directory. A traversal segment cannot survive a membership test against a list the server wrote itself. - Binary payloads are cached hard; the catalog is refreshed.
ETagis the file's SHA-256 out of the manifest andCache-Controlis a year: unlike a subject's surface, this URL's content cannot change under a client without the installation itself changing. The manifest is not cached, so installation updates do not leave the atlas selector using an obsolete catalog. - The space is
guide-ras, and it is in every response. A consumer that mistakes it for a research subject's RAS writes a silently wrong coordinate; saying so on the wire is what lets the desktop pane disable click-to-config instead of trusting a comment.
manifest ¶
The packaged manifest, minus the per-file bookkeeping a client never uses.
files/*_meta/sha256 describe the package (the gate test reads
them off disk); what crosses the wire is the same shape the scene manifest
has, so one pane component can consume either.