refactor: drop /web/ URL prefix from browser routes
The /web/ prefix predated the /api/ split; today it just clutters every URL
without disambiguating anything. All 16 browser routes move to the apex
(/cases, /login, /magic, /events, /audio/...). The 6 /api/* routes are
unchanged. A new /->>/cases redirect closes the apex 404.
The open-redirect guard in magic.rs and case_actions.rs flips from a
positive whitelist (starts_with("/web/")) to a deny-list: same-origin path,
not protocol-relative, not under /api/, no \. The /api/ exclusion is now
load-bearing and covered by tests.
Pre-production: no transition redirects.
This commit is contained in:
@@ -168,7 +168,7 @@ async fn upload_reopens_closed_case() {
|
||||
|
||||
// Close the case by writing the marker directly — simulates the
|
||||
// user hitting the close button in the web UI without having to
|
||||
// drive the /web/cases/{id}/delete handler here. Direct write also
|
||||
// drive the /cases/{id}/delete handler here. Direct write also
|
||||
// means the watermark is NOT bumped here; that way the next GET
|
||||
// /api/oneliners pins down the pre-reopen ETag cleanly.
|
||||
let case_dir = data_path.join("dr_test").join(case_id);
|
||||
|
||||
Reference in New Issue
Block a user