Denya OneCare P0 batch per relay #746 / RA-H node #1903 (captain-approved full go). Scope: POST /api/auth/register removed; admin user-management endpoints (POST/PATCH/DELETE /api/auth/users); unified role model with unknown-role rejection at creation and JWT validation; login rate limiting (5/15min per IP+email to 429); fail-closed X-Webhook-Secret on WhatsApp webhook; mock-log 401/403 (was 500); security headers middleware (XFO DENY, nosniff, CSP, HSTS when TLS); tickets pagination verified with max page size; email normalization end-to-end incl. idempotent startup migration for legacy mixed-case rows + regression test (review-finding fix). no-mistakes validated: review fix round passed, full suite 82 passed. Deploy to CT115 + DB cleanup (probe users 19/20 + ticket 95) executes only after merge.
Denya OneCare P0 batch per relay #746 / RA-H node #1903 (captain-approved full go). Scope: POST /api/auth/register removed; admin user-management endpoints (POST/PATCH/DELETE /api/auth/users); unified role model with unknown-role rejection at creation and JWT validation; login rate limiting (5/15min per IP+email to 429); fail-closed X-Webhook-Secret on WhatsApp webhook; mock-log 401/403 (was 500); security headers middleware (XFO DENY, nosniff, CSP, HSTS when TLS); tickets pagination verified with max page size; email normalization end-to-end incl. idempotent startup migration for legacy mixed-case rows + regression test (review-finding fix). no-mistakes validated: review fix round passed, full suite 82 passed. Deploy to CT115 + DB cleanup (probe users 19/20 + ticket 95) executes only after merge.
- Remove POST /api/auth/register (404); no sign-up UI; users are admin-managed
- Add admin-only POST/PATCH/DELETE /api/auth/users (forced canonical roles,
self-lockout + reference guards)
- Unify role model in app/core/roles.py; reject unknown roles at creation and
at login/JWT validation; startup normalizes unambiguous legacy aliases
- Login rate limiting ~5 fails/15 min per IP+email -> 429 (in-process, tunable)
- WhatsApp webhook requires X-Webhook-Secret; fail-closed when env unset;
GET handshake uses constant-time verify token (403 on mismatch)
- GET /api/whatsapp/mock-log now requires auth
- Security headers middleware: X-Frame-Options DENY, nosniff, CSP on HTML,
HSTS behind TLS
- Pagination: limit alias for page_size, hard cap enforced, both -> 422
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Denya OneCare P0 batch per relay #746 / RA-H node #1903 (captain-approved full go). Scope: POST /api/auth/register removed; admin user-management endpoints (POST/PATCH/DELETE /api/auth/users); unified role model with unknown-role rejection at creation and JWT validation; login rate limiting (5/15min per IP+email to 429); fail-closed X-Webhook-Secret on WhatsApp webhook; mock-log 401/403 (was 500); security headers middleware (XFO DENY, nosniff, CSP, HSTS when TLS); tickets pagination verified with max page size; email normalization end-to-end incl. idempotent startup migration for legacy mixed-case rows + regression test (review-finding fix). no-mistakes validated: review fix round passed, full suite 82 passed. Deploy to CT115 + DB cleanup (probe users 19/20 + ticket 95) executes only after merge.