2 Commits
Author SHA1 Message Date
thethreemagi d1dfa6df90 API.md ships in the image; GET /api/docs/approved serves it behind api:docs
Moved to app/API.md so the build context carries it. The console renders
it at /leaders/api. tests/smoke_admin.py 162 -> 164.
2026-09-04 20:26:45 -04:00
thethreemagi 38bedaea88 API.md: every admin route driven over HTTP and approved; tests/http_drive.py
48 routes plus /api/docs, 123 checks over real HTTP against a throwaway
site on a copy of the live database, as anonymous, a member, a pack
leader, an admin (the claude account), the owner, and the break-glass
token from the LAN and from outside. Every refusal path the routes
promise was exercised: 401, 403 by capability and by unit scope, 404,
409 state conflicts, 422 validation, and 502 when the publisher refuses
a bad signature. Calendar probes went to the real Radicale store dated
2036 and were deleted; the store ended with 32 objects and none in the
site namespace. API.md is generated from the router registry plus those
results, one entry per route with its own description and what was
tried. No route failed; all 48 approved.
2026-09-04 20:24:31 -04:00