b176a44627
Active docs/ was stub scaffolding while the real docs sat in docs/_archive/. Restore and correct them, and record the Phase 0 work. - docs/architecture/current.md: verified system map (from archived SYSTEM_OVERVIEW, 9 corrections against code). - docs/research/competitors.md: sourced competitor analysis (from archived PRODUCT_RESEARCH, feature matrix corrected). - docs/decisions/ADR-002-job-application-model.md: the Job/JobApplication split. - docs/application-discovery-report.md, docs/implementation-roadmap.md, docs/phase-0-foundation-report.md, docs/career-workspace-branch-assessment.md. - Remove 10 zero-byte placeholder files that advertised content that never existed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
468 B
468 B
Authorization
Purpose
Control access to resources.
User Isolation
A user must only access:
- Their jobs.
- Their CV.
- Their files.
- Their emails.
- Their settings.
Admin Role
Admins may access:
- System settings.
- Provider configuration.
- Monitoring.
API Rules
Every protected endpoint must verify:
- User identity.
- User permission.
- Resource ownership.
Never Trust Frontend
The backend must enforce permissions.