Delete the public /api/config/gemini endpoint and remove client auto-load paths so GEMINI_AI_API_KEY stays server-side only. Add a scan rate-limit class for the upcoming server-side identify route and a CI gate that blocks reintroducing config key leaks or new browser LLM URLs. Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|---|---|---|
| .. | ||
| api-routes.mdc | ||
| auth-and-permissions.mdc | ||
| db-and-schema.mdc | ||
| no-go-zones.mdc | ||
| schema-map.mdc | ||
| ui-and-theming.mdc | ||