Tools are pinned in mise.toml. ruff.toml points first-party detection at backend/, since the frontend's src/auth, src/books and src/notes otherwise get matched as first-party. biome.json uses spaces to match the existing Prettier-style formatting. Also combines a nested with in test_passwords.py (ruff SIM117).
Limit request bodies to 1 MiB (413 JSON), wire aria-describedby on the
login form, add Retry and cancellation to the book form load, disable
Add entry while a note POST is in flight, and poll pg_isready in README.
Claude-Session: https://claude.ai/code/session_01M9MLit5Ko3X4s7rzC5Kv7X
Implements password hashing with PBKDF2-SHA256 and pepper-based additional security.
Includes password verification, rehash detection, and pepper loading from environment
or file.
Claude-Session: https://claude.ai/code/session_01M9MLit5Ko3X4s7rzC5Kv7X
Session validation now also checks created_at so the 12-hour cap holds
while expires_at is still in the future. Genre seed avoids ON CONFLICT,
which burns SMALLSERIAL values on every startup.
Spec covers data model, API, auth, frontend, error handling, and testing.
ADR-0001 records PBKDF2 + pepper (FIPS) over argon2; ADR-0002 records
revocable server-side sessions over Flask's signed cookie.