cf2962fd67375bfa67a08db9dd34173d1b2dd935
Add a duress password (DISTRESS_PASSWORD env): entering it at login trips an in-memory full lockdown — all new logins (password + passkey) and every existing session are refused until the server is restarted, and the login itself returns a normal "invalid credentials" so it gives nothing away. Also add POST /api/auth/blacklist-token as a clearly-named alias for revoking the current JWT (same effect as signout). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Description
No description provided
42 MiB
Languages
TypeScript
90.9%
Shell
4.7%
JavaScript
4.1%
CSS
0.2%
HTML
0.1%