Repository navigation
v0.1.3: admin sign-in (security)
Security release. Versions 0.1.2 and older had no admin authentication. Anyone who could reach a running instance could start paid lookups and finds on your looot balance, as often as they liked, and download the stored results. If you run 0.1.2 or older on a reachable host, upgrade to 0.1.3 and set TECHSTACK_ADMIN_PASSWORD.
What changed
- Every page and API route is public on purpose or admin. Admin routes need a signed session cookie, and state-changing requests also need a CSRF token and a same-origin request.
- Without TECHSTACK_ADMIN_PASSWORD (12+ characters) admin routes answer 503 and /login shows a setup page.
- /api/lookup and /api/find need the quote total the caller was shown (quoteMicros). The server prices the request again, refuses if the price went up, and caps the run at the lower of that total and spendCapUsd.
- An identical paid request is answered from the stored result for 24 hours and calls looot zero times. A caller idempotencyKey used for a different request gets 409. One session can start 10 paid requests per 10 minutes.
Upgrading: set TECHSTACK_ADMIN_PASSWORD. A script that posted only { text } to /api/lookup now gets a 400 asking for a quote. See "Securing a deployment" in the README.