Removes four unauthenticated dev endpoints that were shipped to production: - pages/api/simple.js (info leak) - pages/api/test-auth.js (auth diagnostic / token-mint side door) - pages/api/test-db.js (DB connection diagnostic) - pages/api/setup-database.js (public POST that ran DDL + seeded admin) setup-database is the highest-impact removal: it was a public endpoint that triggered schema bootstrap and seeded the default admin credentials (admin@tcgvault.com / admin123). AGENTS.md gotcha #5. Also adds a new `forbidden-endpoints` job to .github/workflows/ci.yml that fails the build if any of the four deleted paths re-appear OR if any new pages/api/test-*.js file is added. Cheap insurance against a future agent re-introducing a dev endpoint from an outdated tutorial. README: drops the single `GET /api/test-db` line under "Health Check". Rest of the API list is intentionally left for the doc-writer pass. Verified locally: - npm run build exits 0 (no source callers — confirmed via grep across pages/, components/, lib/) - CI guard local simulation: clean → OK; with test-fake.js → FAIL; OK after cleanup Resolves AGENTS.md gotcha #5. Brief 1/2/4/5 still pending in convoy. Convoy: fix-auth-bypass / Brief 3 Co-authored-by: Cursor <cursoragent@cursor.com> |
||
|---|---|---|
| .. | ||
| workflows | ||
| CODEOWNERS | ||
| PULL_REQUEST_TEMPLATE.md | ||