Delete the public /api/config/gemini endpoint and remove client auto-load paths so GEMINI_AI_API_KEY stays server-side only. Add a scan rate-limit class for the upcoming server-side identify route and a CI gate that blocks reintroducing config key leaks or new browser LLM URLs. Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|---|---|---|
| .. | ||
| admin | ||
| auth | ||
| cards | ||
| collections | ||
| community | ||
| decks | ||
| invite | ||
| public | ||
| user | ||
| users | ||
| auth-utils.js | ||
| collections.js | ||
| decks.js | ||
| favorites.js | ||
| health.js | ||
| user-cards.js | ||