asepharyana 1ec860f9be fix: audit round 3 — IDOR report-scoping, auth rate-limit, briefing chat scoping, DailyVolumes dedup, N+1 list routines, FE export/ask error handling
- IDOR: interrogate without report_id now scoped to user_key (LatestReportForUser); regression test TestInterrogateIDORScoped
- auth: signup/login per-IP rate limit 10/60s (new internal/api/ratelimit.go) + test
- chat unscoped grounding: build caller's own briefing instead of global LatestBriefing
- DailyVolumes: dedupe by bar date (snapshot rows hold 30-day windows) — fixes volume-anomaly skew
- GetDestination: direct (id,user_key) query instead of listing all
- ListRoutines: single LastRunsByRoutine query instead of N+1 RunHistory
- FE: exportMd/ask/HTML/PDF export now surface errors; alerts create clears channels
2026-09-16 14:12:32 +07:00
2026-09-16 01:27:43 +07:00

docs index

Spec-driven source of truth. Code follows these docs; docs change before code.

Doc Contents
PLAN.md Concept: Autopilot Routines, Verifiable AI, Accuracy Ledger; agents, features, architecture, data model, routes, pages, rules, timeline, verification, risks
API-REFERENCE.md All 70 Sectors v2 paths with params, costs, FlowSight usage, per-cycle credit budget
TECH-STACK.md Pinned versions, deps, why-chosen, declined alternatives, CI gates
ARCHITECTURE.md Backend/frontend layout, scheduler, agent contracts, citation pipeline, SSE design
ROUTINES.md 7 routine specs: schedule, inputs, detection logic, delivery format
AGENT-SPECS.md 7 agent contracts: inputs, processing steps, outputs, verification fixtures
DATA-MODEL.md Table schemas, indexes, retention, seed strategy
API.md Backend route specs: request/response shapes, errors, auth
DEMO-DECK.md Offline demo narrative: briefing → radar → report → interrogation
S
Description
No description provided
Readme
9.1 MiB
Languages
Go 73%
TypeScript 25.6%
Nix 0.6%
CSS 0.4%
Shell 0.3%