fix: 404 unknown API routes, add .dockerignore
- Add catch-all 404 handler for unknown /api/* routes after API mounts - Unauthed requests to unknown API paths now return 401, authed return 404 - Add .dockerignore to prevent leaking data/ (DB, secret.key), .git/, node_modules/ - Add test in auth.test.ts verifying unknown /api/nope returns 401 unauthed, 404 authed Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -21,6 +21,7 @@ export function createApp(deps: Deps) {
|
||||
app.route("/api", authRoutes({ db: deps.db }));
|
||||
app.route("/api", settingsRoutes(deps));
|
||||
// Later route groups (connectors, chat) mount here.
|
||||
app.all("/api/*", (c) => c.json({ error: "not found" }, 404));
|
||||
app.use("/*", serveStatic({ root: "./web/dist" }));
|
||||
app.get("/*", serveStatic({ path: "./web/dist/index.html" }));
|
||||
return app;
|
||||
|
||||
Reference in New Issue
Block a user