• Your Name's avatar
    Fix proper token scoping and permission enforcement · 46faac95
    Your Name authored
    Now:
    - Global tokens (aisbf.json) ONLY access global endpoints
    - User tokens (database) ONLY access their own /api/u/<username> endpoints
    - No cross-access possible
    - Admin users still have full access
    46faac95
main.py 557 KB