Fix: Make TOTP optional when not configured β prevents locking out existing SuperAdmins
b9169bd
AuthorBotcommited on
Fix: JSONResponse args reversed causing all exception handlers to crash with TypeError
8471fa1
AuthorBotcommited on
Production hardening: JWT blacklist, TOTP, Pydantic schemas, Prometheus, SSRF fix, CSP, Redis auth, Celery backup β 35 items across P0-P5
131d826
AuthorBotcommited on
Enforce strict SuperAdmin vs Author panel separation.
6e276e0
AuthorBotCursorcommited on
Fix token display for unsubscribed authors and add SuperAdmin author removal.
cf196a9
AuthorBotCursorcommited on
Unify token tracking, smart links, and personality settings across admin and chat.
a825fee
AuthorBotCursorcommited on
Fix logout on page refresh by restoring sessions via refresh token and cookies.
ccbebe0
AuthorBotCursorcommited on
Harden chatbot against jailbreaks, prompt injection, piracy requests, and response leaks.
ba51f8f
AuthorBotCursorcommited on
Enforce brief sales-focused chatbot rules with spoiler guard and buy CTAs.
701aaf2
AuthorBotCursorcommited on
Restructure chat flow: hello shows clickable book list, then engaging Q&A.
0daa940
AuthorBotCursorcommited on
Humanize bot responses for greetings, catalog questions, and empty RAG retrieval.
2bb94f4
AuthorBotCursorcommited on
Fix revoke subscription hang caused by blocking SMTP email send.
2e8c5a3
AuthorBotcommited on
Fix auth session expiry with shared auto-refresh client for admin panels.
e70f2c6
AuthorBotcommited on
Fix chat session init crash and improve embed reliability
2b2591e
AuthorBotcommited on
fix: naive vs aware datetime error in grants/extend/embed-token, grant button loading state + 15s timeout + token display modal
7e0e662
AuthorBotcommited on
feat: Per-user auto embed token, full Token Management SA page, fix extend on expired subs, add /grants + /reset-tokens + /embed-token endpoints
8916c9a
AuthorBotcommited on
Fix CSS: sidebar now scrollable with thin scrollbar, tooltips drop DOWN instead of up to stay in viewport
05614e4
AuthorBotcommited on
CRITICAL: safe rollback in get_db - session.rollback() was masking HTTPException(401) when no transaction active, causing bare 500 responses
b5db918
AuthorBotcommited on
Add QoL info tooltips to SuperAdmin panel, match admin panel design
1105a2b
AuthorBotcommited on
CRITICAL FIX: use HTTPException(401) instead of custom InvalidTokenError in get_current_user - FastAPI handles HTTPException natively in dependency injection, custom exceptions were escaping to bare 500
630918d
AuthorBotcommited on
Major hardening: bulletproof superadmin router with try/except on every endpoint, fix exception handler names, validate tokens before dashboard, add QoL info tooltips to all admin pages
7d736db
AuthorBotcommited on
Fix SuperAdmin 500 errors: harden get_current_user against null/undefined/expired tokens, return 401 instead of 500; harden SuperAdmin apiGet/apiPost with defensive JSON parsing and 401/403 redirect to login; fix grant_access serialization
ed8ccd5
AuthorBotcommited on
Fix grant_access return: was returning raw SQLAlchemy model, now returns JSON-serializable dict matching AccessGrantResponse schema
Fix 500 errors: analytics/funnel used non-existent event_type, analytics/intents used non-existent metadata_json. Add defensive JSON parsing to all API helpers to prevent 'Unexpected token' errors
8ef4618
AuthorBotcommited on
Phase 1.2+5.1+6.2+6.5: Book cover upload with resizing, conversion funnel analytics, intent distribution, backup system, CI/CD pipeline
e00a1e3
AuthorBotcommited on
Convert ALL middleware to pure ASGI: eliminate BaseHTTPMiddleware completely to fix request body consumption bug causing 500 on ALL endpoints
59a89d6
AuthorBotcommited on
Fix SecurityHeadersMiddleware: rewrite as pure ASGI to avoid BaseHTTPMiddleware request body consumption bug
Fix critical bugs: remove duplicate showModal/closeModal override, fix FastAPI route ordering conflicts (sessions/search before sessions/{id}, qa/import+export before qa/{id}), add missing visitor_name/turn_count to session list response
e759455
AuthorBotcommited on
Phase 1.3+3.2: Integrate Custom Q&A into RAG pipeline (Jaccard similarity), add message feedback (ππ) and session rating endpoints for widget
d95db15
AuthorBotcommited on
Phase 1: Add Conversations Viewer, Custom Q&A Manager, Export Center β 15 new API endpoints, 3 new admin pages, CustomQA model, message annotations, flagging, search, CSV import/export
d09ea19
AuthorBotcommited on
Deep audit fix: add missing model columns (blocked, rating, tokens_used, out_of_scope_message, buy_url, preview_url), fix .get() calls, fix ingest doc creation, add track-click endpoint, add column migrations, fix email crash, fix audit log field names, enrich superadmin author list
868f634
AuthorBotcommited on
Wire all frontend features to real backend APIs: widget-config, profile, personality, notifications, smart-links, token-usage, grant-by-email, fix password endpoint