- Require a session on every route; public routes opt out with @allow_anonymous
- Split password hashing and pepper loading into passwords.py
- Add a system/light/dark theme toggle backed by light-dark() colors
- Ignore stale 401s from an earlier session, PATCH only changed book fields,
and block overlapping journal-entry saves
- Add bin/start and CoderPad Vite server settings for the pad's start/restart
- Rewrite README as a mise onboarding guide; expand .gitignore
- Include review-round fixes and tests
Tools are pinned in mise.toml. ruff.toml points first-party detection at backend/, since the frontend's src/auth, src/books and src/notes otherwise get matched as first-party. biome.json uses spaces to match the existing Prettier-style formatting. Also combines a nested with in test_passwords.py (ruff SIM117).
Limit request bodies to 1 MiB (413 JSON), wire aria-describedby on the
login form, add Retry and cancellation to the book form load, disable
Add entry while a note POST is in flight, and poll pg_isready in README.
Claude-Session: https://claude.ai/code/session_01M9MLit5Ko3X4s7rzC5Kv7X
Implements password hashing with PBKDF2-SHA256 and pepper-based additional security.
Includes password verification, rehash detection, and pepper loading from environment
or file.
Claude-Session: https://claude.ai/code/session_01M9MLit5Ko3X4s7rzC5Kv7X