mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-02 21:49:42 +02:00
Replace hardcoded per-IP rate limit (10) and cookie maxAge (86400) in system-routes.ts with QR_AUTH_FAILURE_MAX and AUTH_SESSION_TTL_MS/1000 so both auth paths stay in sync if constants change. Add 16 new tests: grace period boundary precision, base62 charset validation, current+previous token during grace, stopTokenRotation state cleanup, rate limit reset, consumed token eviction, full end-to-end QR flow, per-IP 429, cookie attributes, concurrent race, regenerate invalidation, URL encoding, path traversal, /q without param, and session record method:qr. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>