feat(whatsapp,branding): WhatsApp demo-number wiring + Denya logo assets

WhatsApp demo path (relay #748):
- WHATSAPP_DEMO_TO config under the WhatsApp section (env-based, .env-only;
  .env.example keeps an empty placeholder; real numbers never enter source).
- build_demo_webhook_payload() in app/routers/whatsapp.py builds the Meta
  demo payload from it (fails closed when unset), so the webhook round trip
  logs from_number = demo number (surfaces in GET /api/whatsapp/mock-log) and
  the auto-reply targets the same number.
- tests/test_whatsapp_demo_number.py: default empty + never committed in
  tracked files, payload builder from/to, 200/403/401 gates unchanged.

Branding (logo-assets-v1, sha256-verified, same-origin app/static/branding):
- Login header uses h96 full lockup; logged-in topbar (base.html) uses h48 on
  a light chip (logo ink is ~2:1 vs the dark nav); favicons 32x32 + 16x16 in
  <head>. img-src 'self' data: blob: already allows /static/branding/*.
- tests/test_branding_assets.py: page placement + same-origin serving + CSP.
- AGENTS.md synced.
This commit is contained in:
root
2026-09-09 19:32:21 +00:00
parent f1428335ef
commit a6eb799efa
15 changed files with 330 additions and 13 deletions
+7
View File
@@ -20,6 +20,13 @@ META_GRAPH_BASE=https://graph.facebook.com/v18.0
# Generate with: openssl rand -hex 32
WHATSAPP_WEBHOOK_SECRET=
# ── WhatsApp demo path (optional) ───────────────────────
# Expected sender/recipient number (E.164) for the WhatsApp demo round trip
# (webhook -> ticket -> mock-log). Set the real number ONLY on the deploy
# host's .env — keep this template an empty placeholder, never a live number.
# Empty (default): the demo payload builder fails closed (no fabricated sender).
WHATSAPP_DEMO_TO=
# ── Login rate limiting (P0) ────────────────────────────
# ~5 failed login attempts per 15 minutes per IP+email → HTTP 429
LOGIN_RATE_LIMIT_MAX_ATTEMPTS=5