- Remove dead kitchen->KDS internal API (api/internal.py, verify_internal_secret)
— KDS reads kitchen_db directly (E16), nothing ever called this endpoint
- Add expires_at to dispute_attachments; public attachment links now expire
after 30 days instead of staying valid forever (A4)
- Add services/upload_validation.py: sniff real file content via python-magic
instead of trusting the client-supplied Content-Type header, plus a 20MB
cap. Applied across invoices/logbook/food_flags/credit_notes/disputes
upload endpoints (A5) — disputes previously had no file-type check at all
- Fix nginx client_max_body_size drift (800m -> the plan's intended 20m)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Query was used at lines 2121 and 2242 (token query-param auth on image preview
endpoints) but never imported, causing the backend to crash on startup.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Migrated all 435 frontend fetch calls from Authorization Bearer header to credentials: 'include' (cookie auth)
- Removed ?token= from all file/image URLs (browser history exposure)
- Added ProtectedRoute wrapper to all capability-gated routes in App.tsx
- OCR background task: added transaction boundary, improved error handling and status rollback
- DuplicateDetector: wrapped in non-fatal try/except so crashes don't abort invoice processing
- File upload: commit DB row before writing to disk to prevent orphaned files
- GP% clamped to 100% in GPReport (credit notes can inflate above 100%)
- Added CSV export to GPReport (suppliers, daily data, allowances breakdown)
- Backend file-serving endpoints: cookie auth with ?token= fallback for backward compatibility
- DATA_DIR: moved from hardcoded /app/data to os.getenv in invoices.py and recipes.py
- N+1 fix in list_recipes: batch-loads latest cost snapshot in 1 query (was N)
- Zero-yield sub-recipe: logs warning instead of silently zeroing cost contribution
- Budget spend rate input: rejects negative values
- GPReport allowances toggle: persisted to localStorage across page loads
- DB pool_size/max_overflow: configurable via DB_POOL_SIZE/DB_MAX_OVERFLOW env vars
- Fixed SyntaxWarning from \\d in invoices.py docstring
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The in-app page-restriction system (admin-only toggles in Settings) was
nav-hiding only and duplicated functionality already covered by JWT caps
in the main stack auth service. All 9 pages in the restriction list were
already gated in Layout.tsx by existing caps.
Backend: add router-level requireCap() to enforce caps at the API layer:
- reports.py: Depends(require_cap("view"))
- logbook.py: Depends(require_cap("logbook"))
- search.py: Depends(require_cap("invoices"))
Frontend: remove the Access Control settings section entirely:
- Drop pageRestrictions query, restrictedPages/accessSaveMessage state,
savePageRestrictionsMutation, isSectionAccessible helper
- Remove 'access' from SettingsSection type and sidebarItems
- Strip restrictPath from all sidebar items (no longer needed)
Access management is now fully centralised in the main stack auth service.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- settings/src/integrations/schema.js: rename azure from 'Azure AD' to
'Azure Document Intelligence', swap fields to endpoint + api_key
- Add use_global_azure column (migration + model)
- global_settings_service: add azure to check_global_status and apply_global_overrides
- api/settings.py: expose use_global_azure in response/update; apply overrides
in test_azure_connection before credential check
- Settings.tsx: add 'Use credentials from main stack settings' toggle for
Azure OCR section (endpoint/key disabled when on, test button enabled when
global is configured); remove Users section (managed centrally via auth
service), clean up UserData interface, users query and mutations
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Each of Newbook, Resos, SambaPOS, SMTP, and Nextcloud now has a checkbox at the
top of its credentials block. When enabled, the app reads auth credentials from
the central stack settings service (SETTINGS_URL + STACK_INTERNAL_SECRET) and
the local auth fields are grayed out. App-specific fields (base path, GL codes,
keywords, sync intervals, etc.) remain editable regardless.
Backend: new use_global_* columns on kitchen_settings, migration, global_settings_service
with apply_global_overrides() for in-memory credential injection, GET /api/settings/global-status
endpoint, and apply_global_overrides() called in test-connection endpoints and FileArchivalService.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- /file and /pdf endpoints: make token optional, fall back to hnf_session
cookie auth when no valid JWT token provided. Kitchen frontend passes the
literal '__session__' compat shim so token-only auth always 401'd.
- Add Request injection so cookie-based fallback path can read hnf_session.
- nginx: add types block mapping .mjs → text/javascript so pdf.worker.min.mjs
passes browser strict MIME check for ES module scripts.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Remove stale import of non-existent require_cap_from_token from
get_invoice_file endpoint — caused ImportError → 500 on every PDF load
- Fix pdf.js worker path from '/pdf.worker.min.mjs' to '/kitchen/pdf.worker.min.mjs'
in Review.tsx and SearchDefinitions.tsx — worker was being fetched from domain
root instead of under the /kitchen/ base, causing MIME type rejection
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Frontend sends lowercase status (e.g. 'confirmed'), but the DB enum values
are uppercase (CONFIRMED). Uppercase the parameter before comparison.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- nginx client_max_body_size raised to 800m (was 20m) to allow 577MB backup
upload; proxy_read_timeout raised to 600s for long restore operations
- Add api/kds_settings.py: GET+PATCH /api/kds/settings served by kitchen
backend (kitchen Settings page configures KDS timers/GraphQL/course order;
all config lives in kitchen_settings so kitchen owns these endpoints)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
?token= query-param endpoints (PO/invoice print previews, recipe image exports,
backup download) call get_current_user_from_token which was not ported from the
original archive auth module. Added the function and fixed the missing import in
backup.py, ingredients.py, and invoices.py.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>