Page Registry
Evaluator-facing pages, secured admin areas, and API surface summary.
Submission-Safe Page Registry

Page Registry & Access Review

This registry is prepared for evaluation. It shows public evidence pages clearly, confirms that operational admin pages are protected, and summarizes API/dynamic routes without exposing unnecessary internal details.

Evaluator Pages
7

Safe pages visible without login.

Protected Admin Areas
13

Operational pages require admin login.

API Surface
4

Authenticated API endpoints.

Broken Pages
0

Must remain zero before presentation.

Evaluator-Facing Pages

These pages are intentionally visible for ministry/technical evaluation.

Public Evaluation Scope
Page Purpose Status Readiness
/
https://asp.mazenofficial.net/
Public evaluation landing page. 200 PASS
/admin
https://asp.mazenofficial.net/admin
Evaluation dashboard and platform overview. 200 PASS
/admin/accreditation-readiness
https://asp.mazenofficial.net/admin/accreditation-readiness
Submission readiness matrix and required evidence tracker. 200 PASS
/admin/documentation
https://asp.mazenofficial.net/admin/documentation
Technical, security, API, continuity, and evidence documentation. 200 PASS
/admin/page-registry
https://asp.mazenofficial.net/admin/page-registry
Page access and route readiness summary. 200 PASS
/developers
https://asp.mazenofficial.net/developers
Developer/API integration guide. 200 PASS
/health
https://asp.mazenofficial.net/health
Public health endpoint for uptime verification. 200 PASS

Protected Operational Areas

These areas are intentionally hidden from visitors and require secure admin login. This is expected and should be presented as a security control, not a broken page.

Area Access
API Clients & OnboardingAdmin Login Required
Documents & Evidence PackagesAdmin Login Required
Webhooks & API LogsAdmin Login Required
Audit Ledger & AnchorsAdmin Login Required
Backups & Restore RunbookAdmin Login Required
Operations / Health / Security AlertsAdmin Login Required

API Surface Summary

API endpoints are not public browsing pages. They require API authentication and source controls.

  • API Key Authentication
    Requests require X-ASP-API-KEY.
  • Source Tenant Domain
    Requests must match allowed tenant domain.
  • IP Allowlist
    Client traffic can be restricted by source IP/CIDR.
  • Idempotency
    Safe retries using Idempotency-Key.

Dynamic Evidence Routes

Dynamic routes require existing records such as document UUID, API client ID, webhook delivery ID, request ID, or backup file name. They are reviewed during live demo after test data is created.

Dynamic Capability Example Route Pattern Review Timing
Document Details/admin/documents/{uuid}After document exists
Evidence Package/admin/documents/{uuid}/evidence-packageAfter document exists
API Client Usage/admin/api-clients/{client}/usageAfter client exists
Webhook Details/admin/webhooks/{delivery}/detailsAfter delivery exists
API Document XML/JSON/api/v1/documents/{uuid}/xmlAfter authenticated API request