ce76046a29
- consolidate API ownership and remove dead vendor code - add Stripe billing, learning paths, and public CV hardening - add migration, recovery, security, audit, and browser gates
536 B
536 B
login
POST /api/auth/login accepts email, password, and remember-me preference. Successful local login
issues an HttpOnly session cookie plus a readable CSRF cookie. Accounts with two-factor authentication
receive a short-lived pending token and must complete POST /api/auth/2fa/challenge before a session is
issued. Login and challenge endpoints are rate-limited.
The frontend route is /login; registration has its own /register route. Authentication errors are
shown without exposing whether an unknown account exists.