Delete the public /api/config/gemini endpoint and remove client auto-load paths so GEMINI_AI_API_KEY stays server-side only. Add a scan rate-limit class for the upcoming server-side identify route and a CI gate that blocks reintroducing config key leaks or new browser LLM URLs. Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|---|---|---|
| .. | ||
| flags | ||
| ai-ocr.js | ||
| auth-secret.js | ||
| mana-symbols.js | ||
| permission-middleware.js | ||
| rate-limit.js | ||
| slug-utils.js | ||
| theme-context.js | ||
| use-auth.js | ||