- Cookie-based auth via backend proxy (httpOnly JWTs) - Supabase Postgres persistence for sessions/messages/profiles + RLS - Fix cross-user session leak (token cache keyed by full token, not 50-char prefix) - Fix missing table grants (42501) via migration; auto-provision profiles on user creation - Chat validation, ownership checks, rate limiting, /api/chat/sessions route ordering - Frontend auth-state reset + credentials include - OpenRouter AI provider (OpenAI-compatible base URL, reasoning disabled) - Tests: chatValidation, appState
9 lines
72 B
Plaintext
9 lines
72 B
Plaintext
# Supabase
|
|
.branches
|
|
.temp
|
|
|
|
# dotenvx
|
|
.env.keys
|
|
.env.local
|
|
.env.*.local
|