main #1
Loading…
Reference in a new issue
No description provided.
Delete branch "main"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
- Verify page auto-sends a new code on load when the account is unverified and no code was sent in the last 60s, fires once per session, and resumes an in-progress countdown on reload - 60s resend cooldown: button disabled with live countdown, shows last-sent time ("Code sent at HH:MM — request another in Xs", then "Code last sent at HH:MM") - Register records send time before redirecting so first arrival at /verify doesn't send a duplicate email - Cooldown state is client-side localStorage; server's 3/hour per-IP resend rate limit remains the real cap - New verifyCooldown util with unit tests (8 cases)Delete the app's 71 /api endpoints (src/routes/api/**) and the three server modules only they used (ratelimit, email, contentFilter). The Hono api service now owns the API surface for web + iOS on every environment. - Port the 4 debug UI mirrors (/api/debug/ui/{homepage,admin,account, closure}) and an /api/health alias into the api service, with smoke tests - Add CORS middleware to Hono (CORS_ORIGINS env, default *) - docker-compose.prod.yml + docker-compose.yml: add the api service with Host && PathPrefix(/api) routing and the shared photo volume (local fallback path unchanged for existing prod photos) - .env.production.example documents S3/CORS/ARCGIS_CRON_ENABLED - Bump SW api cache to v16 (backend swap invalidation) - playwright: E2E_BASE_URL support to run e2e against a deployed env (local preview no longer serves /api) Verified: app 515 tests, api 167 tests, svelte-check clean, composes valid.