fszontagh
|
5930dbc761
feat(errors): add 409 Conflict and structured error details
|
1 month ago |
Fszontagh
|
956c2df2bf
fix(auth): allow X-Captcha-Token/Cache-Control in CORS; reject admin+scope via PATCH
|
3 months ago |
Fszontagh
|
fb86e96005
feat(auth): CAPTCHA verification on require_human_token operations
|
3 months ago |
Fszontagh
|
105cbb5774
fix(auth): deny scoped keys on collection-management routes (requireProjectManage)
|
3 months ago |
Fszontagh
|
f3f29fcb32
feat(auth): requireCapability (scope rule + origin + rate-limit) + Retry-After
|
3 months ago |
Fszontagh
|
5bb842b26f
feat(auth): expired scoped keys fail authentication (401)
|
3 months ago |
Fszontagh
|
ede4cef690
fix(server): SPA history fallback — serve index.html for client-side routes
|
3 months ago |
Fszontagh
|
26af36abad
feat(docs): serve offline rendered API docs at /docs + web UI link
|
3 months ago |
Fszontagh
|
4ef3333fd1
feat(api): admin GET/PUT /api/v1/settings (masked secret) + client methods
|
3 months ago |
Fszontagh
|
70023f26c3
fix: CORS multi-origin, limit/offset 422, project-delete cleanup, env key persist, last-admin guard
|
3 months ago |
Fszontagh
|
68a84eebc8
feat(server): project-aware auth (authn pre-routing + per-handler authz), CORS, meta, login
|
3 months ago |