Skip to content

PointSav Documentation

The engineering library for the PointSav platform — operating systems and services for regulated businesses that own their data, their AI, and their record-keeping outright. Where the monorepo holds the code, this wiki holds the reasoning: architecture, services, security, and the governance commitments that bind future development.

Presentation-layer routing and client-side script

← All revisions

c8cbe2ec · PointSav Digital Systems ·

editorial(patterns): rewrite zero-execution-routing to describe real presentation-layer behavior (Track-B) — re-verified directly against live pointsav.com + woodfinegroup.com: both serve a page with real client-side JS (SHA-256 checksum display + navigator.sendBeacon telemetry), directly contradicting the article's 'zero client-side JavaScript'/SOC 3 claim; also confirmed no root-vs-/es/ directory split, single file with checkbox toggle; dropped the false compliance claim, escalated separately to Command (msg command-20260822-active-compliance-relevant-discrepancy-z) since it's a live public compliance claim not an editorial call; register-clean EN+ES

View the full record as of this revision →

@@ -4,48 +4,30 @@ type: topic
content_type: topic
index_group: sovereignty-and-infrastructure-patterns
slug: zero-execution-routing
short_description: "Presentation layers adhere to a zero-execution mandate, eliminating client-side JavaScript via structural determinism for routing and native CSS state machines."
title: "Zero-execution routing and presentation"
short_description: "The platform's public homepage templates use a native-CSS checkbox pattern for language toggling and interactive elements, alongside a small amount of client-side JavaScript for page-integrity display and analytics."
title: "Presentation-layer routing and client-side script"
audience: vendor-public
bcsc_class: current-fact
language: en
paired_with: zero-execution-routing.es.md
category: patterns
last_edited: 2026-05-25
last_edited: 2026-08-22
editor: pointsav-engineering
---

The platform's public homepage templates use native CSS checkbox state — not JavaScript — for their interactive elements: language toggles and download buttons switch visible content via `:checked` selectors rather than a script listening for click events. **A reader toggling between languages on the homepage is not running any script to do it.** That interaction works even with JavaScript disabled entirely. The same templates do carry a small amount of client-side JavaScript for a different purpose: computing and displaying a page-integrity checksum, and reporting basic page-view analytics on navigation away from the page.

## The CSS checkbox pattern

**Correction (2026-08-02) — compliance-relevant claim, does not match real code:** the real closest-matching implementation, `service-content/templates/pointsav-monolith.html` (and its sibling `woodfine-brutalist.html`), directly contradicts the "zero client-side JavaScript"/SOC 3 claim below — it contains a live `<script>` block that computes a SHA-256 hash on toggle and fires `navigator.sendBeacon` telemetry on page unload. There is also no root-vs-`/es/`-directory split anywhere in the repo for any presentation surface checked — the real template embeds both language blocks in one file, toggled by a single checkbox, not the structural two-file split this article describes. The CSS-checkbox toggle mechanism itself is real (confirmed in both templates), but "zero execution latency and no client-side script vulnerability" is false as a description of the real deployed page. **Flagged, not resolved** — this claim invokes SOC 3 compliance directly, so it needs correcting or re-scoping rather than left standing.
Interactive interface elements — language toggles, download-variant buttons — operate on native CSS checkbox state rather than script-driven state. The DOM loads all language blocks and button variants at once; CSS `display` rules tied to a hidden checkbox's `:checked` state show or hide the relevant block. Switching languages or button variants involves no script execution and no page reload — it is a pure CSS state change. The two language blocks currently live in a single template file, toggled by one checkbox, rather than as separate documents at distinct URL paths.

Platform presentation layers adhere to a zero-execution mandate, eliminating client-side JavaScript for core DOM manipulation, language routing, and file serving. This architectural constraint minimizes the attack surface and supports SOC 3 (Service Organization Control 3) compliance by relying entirely on deterministic files and native CSS state management. The pattern complements the [[machine-based-auth|machine-based authentication]] layer and the [[sovereign-ai-routing|sovereign AI routing]] architecture.
## What client-side script the pages do run

## Key Takeaways

- No client-side JavaScript for core DOM manipulation, language routing, or file serving. The zero-execution mandate reduces the presentation-layer attack surface and supports SOC 3 compliance by relying entirely on deterministic static files and native CSS.
- Bilingual routing is structural, not conditional. The English `index.html` sits at the root; the Spanish `index.html` sits at `/es/` with the language-state checkbox `checked` in static HTML — no IP sniffing, no server-side redirect logic.
- Interactive elements (language toggles, download buttons) use native CSS checkbox state machines: all language blocks load simultaneously, and CSS `display: block/none` switches between them on `:checked` state. Result: zero execution latency, zero script injection surface at the presentation layer.
- The pattern pairs with [[machine-based-auth]]. Presentation surfaces that execute no JavaScript cannot be exploited via script injection — authentication occurs at the machine layer, not the browser layer.

## 1. Deterministic Bilingual Routing

The platform avoids the security risks and latency of IP-sniffing scripts or conditional server-side redirects. Language routing is achieved through structural determinism:
* **English (Root):** The primary `index.html` resides in the root directory.
* **Spanish (/es/):** A structurally identical `index.html` resides in the `/es/` sub-directory, with the `checked` attribute natively applied to the language-state checkbox.

## 2. The Pure CSS State Machine

Interactive interface elements, such as language toggles and dynamic download buttons, operate via native CSS checkbox patterns rather than script-driven state:
* **Simultaneous Loading:** The DOM loads all language blocks and button variations simultaneously.
* **Native Switching:** CSS rules (`display: block` / `none`) are tied to the `:checked` state of hidden inputs.
* **Zero Latency:** This method provides the illusion of a high-performance Web 2.0 application with zero execution latency and no client-side script vulnerability.

This approach ensures that platform interfaces are accessible, secure, and instantaneous across all network environments.
The homepage templates load one small inline script for two purposes unrelated to routing or language switching: it computes a SHA-256 checksum of page content for display in the page's metadata block, and it fires a page-view beacon (`navigator.sendBeacon`) when the reader navigates away. **This means the presentation layer is not entirely script-free** — a reader auditing the page's actual behavior will find this script running on both `pointsav.com` and `woodfinegroup.com` today. The checkbox-based routing and toggle behavior described above genuinely runs without script; the checksum display and analytics beacon are a separate, smaller piece of functionality layered on top of that CSS-driven page.

## See also

- [[sovereign-ai-routing]] — the sovereign AI routing architecture that pairs with this zero-execution discipline
- [[machine-based-auth]] — machine-based authentication layer operating in the same zero-trust presentation context
- [[sovereign-ai-routing]] — the sovereign AI routing architecture that pairs with this presentation layer
- [[machine-based-auth]] — machine-based authentication layer operating in the same presentation context
- [[decode-time-constraints]] — decode-time constraints that enforce deterministic execution boundaries
- [[sel4-microkernel-substrate]] — the microkernel substrate that grounds the execution isolation model
Important Information

Corporate structure. PointSav Digital Systems ("PointSav") is currently a trade name of Woodfine Capital Projects Inc. ("Woodfine"), planned to become a wholly-owned Woodfine subsidiary upon incorporation. PointSav does not itself offer, sell, or solicit any security. Any securities offering associated with Woodfine's real-property direct-hold solutions is made exclusively by Woodfine, and only by means of the applicable Private Placement Memorandum.

No investment advice. This wiki's content is provided for engineering, operational, research, and development purposes. Nothing on this wiki constitutes investment advice or a solicitation to invest in any Woodfine partnership or direct-hold solution.

Intellectual property. The PointSav name, trade name, wordmark, and marks, together with all current and future PointSav- and Totebox-branded products, services, and offerings — and the software, source code, documentation, design system, and all related materials — are proprietary to Woodfine and its affiliates, except for components identified as open source. No rights are granted except as expressly set out in a written license or agreement. The full trademark notice appears in the footer of every page on this site.

Open source components. Portions of the platform are made available under permissive open-source licenses identified in the accompanying repository. Use of those components is governed by their respective license terms.

No warranty; informational use. Content on this wiki is provided for general informational purposes only and does not constitute a representation, warranty, or commitment with respect to product functionality, availability, pricing, or roadmap. Some articles describe planned or intended features, capabilities, and milestones — language such as "planned," "intended," "targeted," "may," and "expected" marks this forward-looking content, which is subject to change and does not constitute a commitment regarding future performance.

Confidentiality. Where an article describes an operational or deployment detail that is not intended for public disclosure, that article is not published on this wiki. Content here is general-purpose engineering documentation, not customer-specific configuration.

Jurisdiction. Woodfine Capital Projects Inc. is organized in British Columbia, Canada. References to the Sovereign Data Foundation on this wiki describe a planned or intended initiative only, not a current equity holder or active governance body.

Changes to this notice. PointSav may update this notice from time to time; the version posted on this page governs.

Not a filing system. This wiki is not a securities filing system, an electronic disclosure repository, or a substitute for SEDAR+ or any other regulatory filing system. Formal securities filings are made through the applicable regulatory filing system, not through this wiki.

Full disclaimer. This notice supplements, and does not replace, the full Disclaimers article. In the event of any conflict, the full Disclaimers article governs.

Read the full disclaimer →