auth/2-gate-endpoints
Move /api/pair, /api/apps, and /api/stream/start under the session auth middleware so they require a valid session token. Add app-level permission filtering: non-admin users only see and can stream apps they have been explicitly granted access to. Admins bypass all permission checks. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Description
No description provided
Languages
Rust
70.2%
TypeScript
22.3%
Svelte
5.7%
CSS
0.9%
JavaScript
0.7%
Other
0.2%