Method cards · declared by the desk, checked against its code

desks,
one card each.

A desk that reports live figures owes its reader four things: where the figures came from, how recently it went back for them, what may be done with them, and where on the desk that is set out at greater length. This page is those four answers for every desk in the estate that keeps a WIRING.json, laid out the same way each time so they can be read across rather than one at a time.

of them read an upstream, between them naming distinct hosts; read nothing at all and say so, because “this desk has no upstream” is an answer rather than a card worth leaving out. Your browser never touches of those hosts — a relay on this origin asks them and hands the page what it parsed. A refresh constant is named by of the desks; the other say not declared, in those words, rather than guessing at a cadence.

The figures

Counted off the tree, not typed onto the page.

The front door has long said the estate reads “50+ upstream sources”, which was a claim with no list behind it. The Wires turned that into a counted list by grepping every .js and .php file in the tree. This page is the other half: a grep can say WHICH hosts the code reads, but not what a host publishes, how often a desk goes back to it, or which clause covers the result. Those the desk declares, in its own WIRING.json, and tools/mkwiring.py refuses to believe the declaration — see the method.

The cards

Every desk, the same four questions.

Upstream is every host named in that desk’s own code, with the exact URL the code holds. A filled dot is a host your browser asks itself; a hollow one is a host only a relay on this origin ever speaks to. Refresh is the constant, its value and its file — or the words not declared, which is what a desk that reads on your action says. Licence is the group the legal page puts the result in. Method is the desk’s own account of itself, or an honest note that it has none yet.

The hosts

All , and who asks them.

The same declarations, folded the other way: one row per host rather than one card per desk, so a host two desks read appears once with both named. Asked by is direct when your browser makes the request, relay when a PHP file on this origin does and your browser never touches the host, and both when each happens — usually because the desk reads it live and the share plate reads it again server-side.

The whole of this, as one file, and the one this page reads: sources.json. It is written by tools/mkwiring.py and it is JSON rather than a script for a reason worth knowing — see the method.

Method

How a card is checked, and what it cannot see.

The desk declares, the tool disbelieves

Each desk carries a WIRING.json, and it now carries a sources array and a method block in it. tools/mkwiring.py reads all of them and refuses every claim it cannot stand up: a host must appear in that desk’s files, the exact URL string the declaration quotes must be a literal in each file it names, the direct-or-relay mode is derived from those files rather than taken on trust, and the licence group must be one the legal page still names in the words the card quotes.

Both editions, or neither

A card’s link to a desk’s method section is checked against index.html and indexdark.html. A card that sent a dark reader to a paper anchor would be the estate’s oldest bug wearing a new hat, so the anchor has to exist on both sides before the card can be written.

The undeclared upstream

Everything above is a forward check: it proves what a desk says is true. It cannot catch a desk that quietly reads a host and does not mention it, so the tool asks tools/mkwires.py — the estate’s one rule for “is this something the code reads” — what it attributes to each desk, and every one of those must be declared. Writing a second copy of that rule here is how the two would come to disagree.

What it cannot tell you

That floor is a floor, not a ceiling. A grep needs a read-shaped signal beside the URL, and two desks here hold theirs where it cannot see: the rates desk assigns the Treasury yield-curve URL to a plain constant, and the fire desk keeps its host on one line and the layer’s path on the next. Both declare the host anyway and the forward check proves it real — but a host declared by nobody and written in that shape would be invisible to both tools.

A host named in code is not every host asked

One desk on this page reads a host that appears in no code at all. The dock board follows the CityBikes register’s own gbfs_href, so the third host on any given visit is whichever one the register named that day. Its card says so, and the board itself always prints which host drew it.

Why the data is JSON and not a script

This page fetches sources.json from its own origin. A .js file assigning the same object would save the request, and it was built that way first. It is JSON because tools/mkwires.py greps every .js in the tree for upstream hosts: a script naming fifteen of them made this page look like a sixteenth desk reading all fifteen, and flipped the FAA’s host on that board from relay to both — telling its readers their browser talks to the FAA directly, which it never does. A page about provenance must not be the thing that makes the provenance board wrong.

And what a card is not

A card describes how the data arrives, not whether it is right. That is the publisher’s business, and where a desk and its publisher disagree the publisher is right — which is the legal page’s clause 6, not a sentiment. Nothing here is a safety service, and nothing here is advice.