feat: complete release readiness work

- consolidate API ownership and remove dead vendor code

- add Stripe billing, learning paths, and public CV hardening

- add migration, recovery, security, audit, and browser gates
This commit is contained in:
cesnimda
2026-07-31 16:54:16 +02:00
parent a23c3dfc97
commit ce76046a29
1634 changed files with 6889 additions and 135429 deletions
+7 -1
View File
@@ -1,3 +1,9 @@
# login
TODO: Complete documentation.
`POST /api/auth/login` accepts email, password, and remember-me preference. Successful local login
issues an HttpOnly session cookie plus a readable CSRF cookie. Accounts with two-factor authentication
receive a short-lived pending token and must complete `POST /api/auth/2fa/challenge` before a session is
issued. Login and challenge endpoints are rate-limited.
The frontend route is `/login`; registration has its own `/register` route. Authentication errors are
shown without exposing whether an unknown account exists.