- Remove dead kitchen->KDS internal API (api/internal.py, verify_internal_secret)
— KDS reads kitchen_db directly (E16), nothing ever called this endpoint
- Add expires_at to dispute_attachments; public attachment links now expire
after 30 days instead of staying valid forever (A4)
- Add services/upload_validation.py: sniff real file content via python-magic
instead of trusting the client-supplied Content-Type header, plus a 20MB
cap. Applied across invoices/logbook/food_flags/credit_notes/disputes
upload endpoints (A5) — disputes previously had no file-type check at all
- Fix nginx client_max_body_size drift (800m -> the plan's intended 20m)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The in-app page-restriction system (admin-only toggles in Settings) was
nav-hiding only and duplicated functionality already covered by JWT caps
in the main stack auth service. All 9 pages in the restriction list were
already gated in Layout.tsx by existing caps.
Backend: add router-level requireCap() to enforce caps at the API layer:
- reports.py: Depends(require_cap("view"))
- logbook.py: Depends(require_cap("logbook"))
- search.py: Depends(require_cap("invoices"))
Frontend: remove the Access Control settings section entirely:
- Drop pageRestrictions query, restrictedPages/accessSaveMessage state,
savePageRestrictionsMutation, isSectionAccessible helper
- Remove 'access' from SettingsSection type and sidebarItems
- Strip restrictPath from all sidebar items (no longer needed)
Access management is now fully centralised in the main stack auth service.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>