fix: 404 unknown API routes, add .dockerignore
- Add catch-all 404 handler for unknown /api/* routes after API mounts - Unauthed requests to unknown API paths now return 401, authed return 404 - Add .dockerignore to prevent leaking data/ (DB, secret.key), .git/, node_modules/ - Add test in auth.test.ts verifying unknown /api/nope returns 401 unauthed, 404 authed Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
7
.dockerignore
Normal file
7
.dockerignore
Normal file
@@ -0,0 +1,7 @@
|
||||
data/
|
||||
.git/
|
||||
node_modules/
|
||||
web/dist/
|
||||
.superpowers/
|
||||
*.log
|
||||
*.tsbuildinfo
|
||||
Reference in New Issue
Block a user