Snapshot of the in-flight state that already existed, identically, in both this worktree and the main checkout before this session began: the initial HTTP Client platform implementation (previously untracked), the redis-lab removal, and the JPA / object-storage / notification integration work. Kept separate from this session's HTTP Client review response, which lands in the following commit, so the two bodies of work stay reviewable apart. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
5 lines
294 B
Plaintext
5 lines
294 B
Plaintext
# feature-security-operational-baseline D5 — deny-by-default public path snapshot.
|
|
# SSOT: SECURITY_PUBLIC_PATHS (src/.env) -> SecurityConfig permitAll(); anyRequest authenticated.
|
|
# Update only after review with: ./gradlew updatePublicPathSnapshot -PapprovePublicPathChange
|
|
/api/healthcheck
|