Commit History

Author SHA1 Message Date
  fszontagh 5930dbc761 feat(errors): add 409 Conflict and structured error details 1 month ago
  Fszontagh 956c2df2bf fix(auth): allow X-Captcha-Token/Cache-Control in CORS; reject admin+scope via PATCH 3 months ago
  Fszontagh fb86e96005 feat(auth): CAPTCHA verification on require_human_token operations 3 months ago
  Fszontagh 105cbb5774 fix(auth): deny scoped keys on collection-management routes (requireProjectManage) 3 months ago
  Fszontagh f3f29fcb32 feat(auth): requireCapability (scope rule + origin + rate-limit) + Retry-After 3 months ago
  Fszontagh 5bb842b26f feat(auth): expired scoped keys fail authentication (401) 3 months ago
  Fszontagh ede4cef690 fix(server): SPA history fallback — serve index.html for client-side routes 3 months ago
  Fszontagh 26af36abad feat(docs): serve offline rendered API docs at /docs + web UI link 3 months ago
  Fszontagh 4ef3333fd1 feat(api): admin GET/PUT /api/v1/settings (masked secret) + client methods 3 months ago
  Fszontagh 70023f26c3 fix: CORS multi-origin, limit/offset 422, project-delete cleanup, env key persist, last-admin guard 3 months ago
  Fszontagh 68a84eebc8 feat(server): project-aware auth (authn pre-routing + per-handler authz), CORS, meta, login 3 months ago