feat: complete release readiness work

- consolidate API ownership and remove dead vendor code

- add Stripe billing, learning paths, and public CV hardening

- add migration, recovery, security, audit, and browser gates
This commit is contained in:
cesnimda
2026-07-31 16:54:16 +02:00
parent a23c3dfc97
commit ce76046a29
1634 changed files with 6889 additions and 135429 deletions
+6 -1
View File
@@ -1,3 +1,8 @@
# validation
TODO: Complete documentation.
Validation happens at trust boundaries: controller request DTOs, file uploads, imported URLs, OAuth
state callbacks, AI sidecar authentication, and deployment configuration. Job import and IMAP targets
resolve through SSRF guards that reject private, loopback, link-local, and unsafe redirect targets.
Unhandled failures use Problem Details with a trace ID; expected validation failures retain their
specific 4xx responses. See `docs/security/input-validation.md` and `docs/security/api-security.md`.