kitchen/backend
jtricerolph bcc94024e3 Pre-deploy security/correctness fixes (port log E17)
- Remove dead kitchen->KDS internal API (api/internal.py, verify_internal_secret)
  — KDS reads kitchen_db directly (E16), nothing ever called this endpoint
- Add expires_at to dispute_attachments; public attachment links now expire
  after 30 days instead of staying valid forever (A4)
- Add services/upload_validation.py: sniff real file content via python-magic
  instead of trusting the client-supplied Content-Type header, plus a 20MB
  cap. Applied across invoices/logbook/food_flags/credit_notes/disputes
  upload endpoints (A5) — disputes previously had no file-type check at all
- Fix nginx client_max_body_size drift (800m -> the plan's intended 20m)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-06 14:44:58 +00:00
..
api Pre-deploy security/correctness fixes (port log E17) 2026-08-06 14:44:58 +00:00
migrations Pre-deploy security/correctness fixes (port log E17) 2026-08-06 14:44:58 +00:00
models Pre-deploy security/correctness fixes (port log E17) 2026-08-06 14:44:58 +00:00
ocr Add .gitignore, remove __pycache__ from tracking 2026-07-12 12:16:04 +00:00
services Pre-deploy security/correctness fixes (port log E17) 2026-08-06 14:44:58 +00:00
auth.py Pre-deploy security/correctness fixes (port log E17) 2026-08-06 14:44:58 +00:00
database.py Audit pass: cookie auth migration, route guards, GP% clamp, CSV export, OCR transaction safety, N+1 fix, and cleanup 2026-07-13 10:04:20 +00:00
Dockerfile Pre-deploy security/correctness fixes (port log E17) 2026-08-06 14:44:58 +00:00
main.py Pre-deploy security/correctness fixes (port log E17) 2026-08-06 14:44:58 +00:00
requirements.txt Pre-deploy security/correctness fixes (port log E17) 2026-08-06 14:44:58 +00:00
scheduler.py Initial kitchen scaffold — Phase 1 kitchen port (build-verified 2026-07-11) 2026-07-12 12:15:39 +00:00