refactor: drop /web/ URL prefix from browser routes

The /web/ prefix predated the /api/ split; today it just clutters every URL
without disambiguating anything. All 16 browser routes move to the apex
(/cases, /login, /magic, /events, /audio/...). The 6 /api/* routes are
unchanged. A new /->>/cases redirect closes the apex 404.

The open-redirect guard in magic.rs and case_actions.rs flips from a
positive whitelist (starts_with("/web/")) to a deny-list: same-origin path,
not protocol-relative, not under /api/, no \. The /api/ exclusion is now
load-bearing and covered by tests.

Pre-production: no transition redirects.
This commit is contained in:
2026-05-04 18:36:10 +02:00
parent 3d67cbc1c8
commit 2c6062a53e
43 changed files with 313 additions and 266 deletions
+1 -1
View File
@@ -2,7 +2,7 @@
//! browser session without an interactive password login.
//!
//! Lifecycle: the desktop client calls `POST /api/auth/magic-link` (API-key
//! authenticated), gets a token, opens the browser at `/web/magic?token=…`.
//! authenticated), gets a token, opens the browser at `/magic?token=…`.
//! The web handler removes the token (one-time-use) and installs a regular
//! `WebSession`. TTL is intentionally short — the token only needs to
//! survive the click → browser-launch → first-request round trip.