feat: 1.5.0 prep — API v1 cutover, LICENSE, CHANGELOG, CI
- Remove legacy /api/ mount; all routes now under /api/v1/ only - Update path matchers (CSRF excludes, public routes, audit log, rate limits) - Move standalone routes (/api/network/ips, /api/docs, /api/docs/spec) to v1 - Update openapi.yaml (110 paths), CA pages, and 4 lingering frontend files - Add LICENSE (proprietary EULA), CHANGELOG.md (Keep a Changelog format) - Add .gitea/workflows/ci.yml (test+lint and security audit jobs) - Fix 9 pre-existing no-empty lint errors so CI starts green - Drop ad-hoc scratch reports and *.bak files from repo root All 739 jest tests pass. Lint is clean. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -118,20 +118,18 @@ function csrfValidationMiddleware(req, res, next) {
|
||||
|
||||
// Excluded paths that don't require CSRF validation
|
||||
const excludedPaths = [
|
||||
'/api/totp/verify',
|
||||
'/api/totp/verify-setup',
|
||||
'/api/totp/setup',
|
||||
'/api/v1/totp/verify',
|
||||
'/api/v1/totp/verify-setup',
|
||||
'/api/v1/totp/setup',
|
||||
'/health',
|
||||
'/api/health',
|
||||
'/api/v1/health',
|
||||
// Machine-to-machine: publishing host POSTs here with its own shared-secret
|
||||
// header (X-DashCaddy-Notify-Secret) — browsers never reach this endpoint.
|
||||
'/api/system/update-notify'
|
||||
'/api/v1/system/update-notify'
|
||||
];
|
||||
|
||||
// Normalize /api/v1/... to /api/... so exclusions work with both prefixes
|
||||
const normalizedPath = req.path.replace(/^\/api\/v1\//, '/api/');
|
||||
const isExcluded = excludedPaths.some(path => normalizedPath === path) ||
|
||||
normalizedPath.startsWith('/api/auth/gate/');
|
||||
const isExcluded = excludedPaths.some(path => req.path === path) ||
|
||||
req.path.startsWith('/api/v1/auth/gate/');
|
||||
|
||||
if (isExcluded) {
|
||||
return next();
|
||||
|
||||
Reference in New Issue
Block a user