# Known Limitations

This page lists the confirmed behavior limits and defects in the current go-web-monitor release, each with its trigger and a workaround.

## Watch List

| Limitation | Trigger | Workaround |
|------------|---------|------------|
| URL format changes after a restart | `del example.com` for a site added as `example.com` before a restart fails, because the list now holds the normalized `https://example.com` | Use the full URL when removing, or add sites with the full URL |
| `add` freezes the interface | For an unresponsive target, `add` checks synchronously on the interface thread and can wait up to 10 seconds each for HEAD and GET | Confirm the URL is reachable before adding it |
| Only 404 triggers GET | A server that rejects HEAD with `405` or another status is marked offline directly | Monitor an endpoint that supports HEAD, such as a health-check path |

## SSL Check

| Limitation | Trigger |
|------------|---------|
| `http://` sites always show `N/A` | The prefix is not stripped, so the hostname is parsed incorrectly |
| Sites on a custom port always show `N/A` | Certificates are read from port 443 only, and a hostname that keeps its port yields an invalid address |
| Only the leaf certificate is checked | An intermediate certificate expiring first is not reflected in the days remaining |

## Email

| Limitation | Description |
|------------|-------------|
| CC recipients receive nothing | Cc exists only in the header and `RCPT TO` goes only to the `to` list, so the CC address never actually receives the email |
| No recovery notice | No email is sent when a site comes back online |
| Alert footer links to the old repo name | The footer link points to `github.com/pardnchiu/web-monitor` |
| Plaintext password | `.webMonitor.json` is written with `0644` permissions |

## Interface and Error Feedback

| Limitation | Description |
|------------|-------------|
| Errors do not appear in the panel | `add` / `del` / `smtp` errors are printed with `fmt.Printf` straight onto the tview screen, leaving artifacts; send errors from `test` and alerts go to stderr |
| Fixed check interval | Always every minute |
| No history | Only the latest result is kept, and Uptime is the ratio for the current round |

## Concurrency Safety

The `status` table is not fully protected: `Update()` reads `status` before taking the lock, `Add()` / `Remove()` write `status` and `list` while holding only a read lock, and `GetStatus()` returns the same map for the interface to iterate. When a background check (every minute or `refresh`) overlaps with `add` / `del`, the Go runtime can raise the fatal error `concurrent map read and map write` and exit the program.

To lower the risk, avoid running `add` / `del` while a `refresh` or the per-minute check is in progress.

## Installation

The module name in `go.mod` is `website-monitor`, which does not match the GitHub path, so `go install` does not work; see [Getting Started](/getting-started).
