506058115-cmd
## Summary The Community app still recognizes several routes whose page components are not shipped, but only `oauth-consent` and `pricing` are converted to `not-found` in `routeStateFromUrl()`. For the other recognized page values, the app casts them to `AppPage`. Since the render switch has no branch for them, they fall through to `<ShaderDocumentation>`. At the same time, `active` defaults to `VISIBLE_READY_SHADERS[0]`, so these unrelated URLs display the first Community shader. Affected routes include: - `/purchase/success` - `/claim/designcode` - `/sponsorship` - `/privacy` - `/terms` - `/affiliates` ## Reproduction 1. Run the current Community app with `npm install && npm run dev`. 2. Open, for example, `http://localhost:5173/privacy`. 3. Observe that the URL and privacy SEO metadata remain, but the page body is the first shader's documentation. 4. The same happens for the other routes above. ## Code path - `src/routes.js::resolveAppRoute()` returns distinct page values for these paths. - `src/App.tsx::routeStateFromUrl()` maps only `oauth-consent` and `pricing` to `not-found`, then casts every other value to `AppPage`. - `ThreeUIApp` has branches only for browse, installation, MCP, and not-found; its final branch renders `ShaderDocumentation`. ## Expected behavior Routes whose private/hosted page implementations are intentionally absent from Community should either: - redirect to the corresponding `https://threeui.com/... ` page, or - resolve to the Community 404 page. They should not render an unrelated shader under a legal, purchase, or program URL. A route-level test covering every page returned by `resolveAppRoute()` would also prevent future unhandled page values from reaching the shader fallback.