feat: complete release readiness work
- consolidate API ownership and remove dead vendor code - add Stripe billing, learning paths, and public CV hardening - add migration, recovery, security, audit, and browser gates
This commit is contained in:
+7
-1
@@ -1,3 +1,9 @@
|
||||
# login
|
||||
|
||||
TODO: Complete documentation.
|
||||
`POST /api/auth/login` accepts email, password, and remember-me preference. Successful local login
|
||||
issues an HttpOnly session cookie plus a readable CSRF cookie. Accounts with two-factor authentication
|
||||
receive a short-lived pending token and must complete `POST /api/auth/2fa/challenge` before a session is
|
||||
issued. Login and challenge endpoints are rate-limited.
|
||||
|
||||
The frontend route is `/login`; registration has its own `/register` route. Authentication errors are
|
||||
shown without exposing whether an unknown account exists.
|
||||
|
||||
Reference in New Issue
Block a user