The install service and admin API as built (website#142), plus the two things §2.7.2 got wrong before there was any code to check them against. The top-level directory rule was checking against nothing real. module-uo's release workflow packs module-uo-<version>/, not uo/, so "reject a top-level directory whose name is not the manifest's id" would have refused every bundle that exists. That level is stripped instead - its name belongs to whoever published the bundle, the directory it lands in has to be the id the loader scans for - and what replaces the check is stronger: the UNPACKED module.json must agree with the install manifest about id and version. And tar has to be pinned forward rather than merely depended on. Installing it gets 6.x, which npm audit reports as critical, and the advisory list reads as this feature's own threat model: hardlink traversal via drive-relative linkpath, symlink poisoning, hardlink escape through a symlink chain, PAX size override on GNU long-name headers, decompression DoS. Refusing symlink and hardlink entry types outright is what takes the extractor off most of that list rather than depending on the library to contain them. Also records the measurement behind the two-pass unpack, which was assumed in the plan and is now known: node-tar DOES reject an escaping member, but late. An archive whose fourth member escapes throws and leaves the first three on disk - and the loader only asks whether module.json is present, so a half-unpacked bundle is a module as far as the next boot is concerned. Refreshes api-route-inventory.json (158 -> 166 public) and the route count in BACKEND_DESIGN, and documents module_source_hosts beside the other seeded settings keys - bootstrapped from the environment, owned by the database. Co-Authored-By: Claude <noreply@anthropic.com>
680 lines
14 KiB
JSON
680 lines
14 KiB
JSON
{
|
|
"$comment": "Generated route inventory - the authoritative freeze of the URL surface. Regenerate with `npm run routes:manifest` in website/server; a domain-split PR must produce a zero-line diff here.",
|
|
"public": [
|
|
{
|
|
"method": "GET",
|
|
"path": "/.well-known/assetlinks.json"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/csp-report"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/docs.json"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/health"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/account"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/account/identities"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/account/identities/:provider"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/account/totp/disable"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/account/totp/enable"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/account/totp/setup"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/activity"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/auth/providers"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/auth/providers"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/auth/providers/:id"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/admin/auth/providers/:id"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/bot-activity"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/bot-activity/unban"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/dashboard"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/discord-bot/config"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/admin/discord-bot/config"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/email/config"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/admin/email/config"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/email/connect/callback"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/email/connect/start"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/email/disconnect"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/email/test"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/invites"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/invites"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/invites/:id"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/appeals"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/appeals/:id"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/moderation/appeals/:id/claim"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/moderation/appeals/:id/resolve"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/filter-hits"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/members"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/recent"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/search"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/spam-hits"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/stats/summary"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/user/:discordId"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/user/:discordId/actions"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/user/:discordId/appeals"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/moderation/user/:discordId/notes"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/moderation/user/:discordId/notes"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/modules"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/modules"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/modules/:id"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/modules/:id/disable"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/modules/:id/enable"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/modules/:id/purge"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/modules/restart"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/admin/modules/sources"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/pages"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/pages"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/pages/:id"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/pages/:id"
|
|
},
|
|
{
|
|
"method": "PATCH",
|
|
"path": "/api/v1/admin/pages/:id"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/pages/:id/preview"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/pages/:id/unprotect"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/posts"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/posts"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/posts/:id"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/posts/:id"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/admin/posts/:id"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/posts/:id/announce"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/posts/:id/announce/retry"
|
|
},
|
|
{
|
|
"method": "PATCH",
|
|
"path": "/api/v1/admin/posts/:id/publish"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/posts/upload"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/settings"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/admin/settings"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/settings/:key"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/settings/brand-asset/:slot"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/admin/site-mode"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/uploads"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/users"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/users"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/users/:id"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/users/:id"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/admin/users/:id"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/users/:id/mfa/reset"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/users/:id/trusted-devices"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/users/:id/trusted-devices"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/users/:id/trusted-devices/:deviceId"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/wiki"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/wiki"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/wiki/:slug"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/wiki/:slug"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/admin/wiki/:slug"
|
|
},
|
|
{
|
|
"method": "PATCH",
|
|
"path": "/api/v1/admin/wiki/:slug/publish"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/wiki/:slug/revisions"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/wiki/:slug/revisions/:id"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/wiki/:slug/revisions/:id/restore"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/wiki/categories"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/admin/wiki/categories"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/admin/wiki/categories/:id"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/admin/wiki/categories/:id"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/admin/wiki/tags"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/invite/:token"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/invite/:token/accept"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/login"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/login/totp"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/logout"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/me"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/me/account"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/me/account/identities"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/auth/me/account/identities/:provider"
|
|
},
|
|
{
|
|
"method": "PATCH",
|
|
"path": "/api/v1/auth/me/account/password"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/me/account/recovery-codes/generate"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/me/account/recovery-codes/status"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/me/account/totp/disable"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/me/account/totp/enable"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/me/account/totp/setup"
|
|
},
|
|
{
|
|
"method": "PATCH",
|
|
"path": "/api/v1/auth/me/account/username"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/me/devices"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/me/devices"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/auth/me/devices/:id"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/me/notifications/streams"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/me/notifications/subscriptions"
|
|
},
|
|
{
|
|
"method": "PUT",
|
|
"path": "/api/v1/auth/me/notifications/subscriptions"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/me/sessions"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/auth/me/sessions/:id"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/auth/me/trusted-devices"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/me/trusted-devices"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/me/trusted-devices"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/auth/me/trusted-devices/:id"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/mobile/login"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/mobile/logout"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/mobile/refresh"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/mobile/sso/exchange"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/mobile/sso/start"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/password/forgot"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/password/reset/:token"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/password/reset/:token"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/providers"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/register"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/sso/:provider/callback"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/sso/:provider/link"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/auth/sso/:provider/start"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/auth/sso/totp"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/player/account"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/player/account/identities"
|
|
},
|
|
{
|
|
"method": "DELETE",
|
|
"path": "/api/v1/player/account/identities/:provider"
|
|
},
|
|
{
|
|
"method": "PATCH",
|
|
"path": "/api/v1/player/account/password"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/player/account/totp/disable"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/player/account/totp/enable"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/player/account/totp/setup"
|
|
},
|
|
{
|
|
"method": "PATCH",
|
|
"path": "/api/v1/player/account/username"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/player/appeals"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/player/appeals"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/player/appeals/:id/withdraw"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/player/appeals/eligible"
|
|
},
|
|
{
|
|
"method": "POST",
|
|
"path": "/api/v1/public/contact"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/modules"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/pages/:id/preview/:token"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/pages/:slug"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/posts/:category"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/posts/:category/:idOrSlug"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/settings"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/status"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/version"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/wiki"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/wiki/:slug"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/wiki/categories"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/public/wiki/tags"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/settings/nav"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/api/v1/settings/theme/options"
|
|
}
|
|
],
|
|
"internal": [
|
|
{
|
|
"method": "GET",
|
|
"path": "/health"
|
|
},
|
|
{
|
|
"method": "GET",
|
|
"path": "/internal/bot-config"
|
|
}
|
|
]
|
|
}
|