== A. the four public surfaces == PASS the public calendar page rendered PASS the Event Link page rendered PASS the standalone calendar page rendered PASS the follow page rendered PASS public-calendar: offers the canonical Privacy Policy PASS public-calendar: offers the canonical Terms of Use PASS public-calendar: the legal links are absolute HTTPS calee.com.au URLs PASS public-calendar: no query string, fragment or path suffix on the legal URLs PASS public-calendar: no calendar token, reference or source URL in a legal URL PASS public-calendar: no analytics or tracking was added PASS event-link: offers the canonical Privacy Policy PASS event-link: offers the canonical Terms of Use PASS event-link: the legal links are absolute HTTPS calee.com.au URLs PASS event-link: no query string, fragment or path suffix on the legal URLs PASS event-link: no calendar token, reference or source URL in a legal URL PASS event-link: no analytics or tracking was added PASS standalone-calendar: offers the canonical Privacy Policy PASS standalone-calendar: offers the canonical Terms of Use PASS standalone-calendar: the legal links are absolute HTTPS calee.com.au URLs PASS standalone-calendar: no query string, fragment or path suffix on the legal URLs PASS standalone-calendar: no calendar token, reference or source URL in a legal URL PASS standalone-calendar: no analytics or tracking was added PASS follow: offers the canonical Privacy Policy PASS follow: offers the canonical Terms of Use PASS follow: the legal links are absolute HTTPS calee.com.au URLs PASS follow: no query string, fragment or path suffix on the legal URLs PASS follow: no calendar token, reference or source URL in a legal URL PASS follow: no analytics or tracking was added == B. error and non-active states stay safe and still offer the documents == PASS the public calendar error page rendered PASS the Event Link invalid page rendered PASS the follow error page rendered PASS public-calendar (error): offers the canonical Privacy Policy PASS public-calendar (error): offers the canonical Terms of Use PASS public-calendar (error): the legal links are absolute HTTPS calee.com.au URLs PASS public-calendar (error): no query string, fragment or path suffix on the legal URLs PASS public-calendar (error): no calendar token, reference or source URL in a legal URL PASS public-calendar (error): no analytics or tracking was added PASS event-link (invalid): offers the canonical Privacy Policy PASS event-link (invalid): offers the canonical Terms of Use PASS event-link (invalid): the legal links are absolute HTTPS calee.com.au URLs PASS event-link (invalid): no query string, fragment or path suffix on the legal URLs PASS event-link (invalid): no calendar token, reference or source URL in a legal URL PASS event-link (invalid): no analytics or tracking was added PASS follow (error): offers the canonical Privacy Policy PASS follow (error): offers the canonical Terms of Use PASS follow (error): the legal links are absolute HTTPS calee.com.au URLs PASS follow (error): no query string, fragment or path suffix on the legal URLs PASS follow (error): no calendar token, reference or source URL in a legal URL PASS follow (error): no analytics or tracking was added PASS the public calendar error page leaks no source URL PASS the Event Link invalid page leaks no reference internals PASS the follow error page leaks no subscription URL == C. the embedded ?ics= route is deliberately NOT changed == PASS the embedded calendar still renders PASS the embedded calendar does NOT gain a legal footer PASS the embedded calendar keeps its existing footer == D. the legal URL is fixed, not derived == PASS public-calendar: a spoofed Host does not reach the legal link PASS event-link: a spoofed Host does not reach the legal link PASS standalone-calendar: a spoofed Host does not reach the legal link PASS follow: a spoofed Host does not reach the legal link == E. one URL, not four == PASS public-calendar: emits exactly the two canonical legal URLs and nothing else PASS event-link: emits exactly the two canonical legal URLs and nothing else PASS standalone-calendar: emits exactly the two canonical legal URLs and nothing else PASS follow: emits exactly the two canonical legal URLs and nothing else PASS public-calendar/err: emits exactly the two canonical legal URLs and nothing else PASS event-link/invalid: emits exactly the two canonical legal URLs and nothing else PASS follow/err: emits exactly the two canonical legal URLs and nothing else == F. nothing else moved == PASS public-calendar.php: the legal URLs are literals, not built from anything PASS public-calendar.php: no request value is concatenated onto a legal URL PASS event-link.php: the legal URLs are literals, not built from anything PASS event-link.php: no request value is concatenated onto a legal URL PASS calendar-embed.php: the legal URLs are literals, not built from anything PASS calendar-embed.php: no request value is concatenated onto a legal URL PASS calendar-follow.php: the legal URLs are literals, not built from anything PASS calendar-follow.php: no request value is concatenated onto a legal URL PASS calendar-embed.php renders the legal footer only in standalone mode public legal link tests passed