wiki: fix wrong auth/OIDC recipes; add download + CWA learnings Accuracy fixes (current recipes are wrong and harmful): - Recover-admin: remove the bcrypt password-hash recipe (Bindery is argon2id-only; a bcrypt hash is silently rejected). Replace with the admin reset-password endpoint and the delete-users setup-wizard path. - Fix the user-role endpoint everywhere: PUT /auth/users/{id}/role (not the bare PUT /auth/users/{id}). - Rotate-OIDC-secrets: the per-provider-id PUT/POST endpoints do not exist; the API is a whole-array GET/PUT. Rewrote to read-modify-write the full array, with a warning that a single-provider PUT deletes all other providers. Fix session-secret rotate path to POST /auth/session-secret/rotate. - Troubleshooting: multi-user 'User A sees User B data' is the documented default (BINDERY_ENFORCE_TENANCY defaults off), not a bug. Added learnings: - SAB/NZBGet now upload NZB content (addfile / base64 append) so the client never needs to reach the indexer. - History tab now records scheduler auto-grabs (#938). - 'connection refused' diagnostics: interface-binding / host-firewall framing (not Docker-subnet). - CWA ingest folder (cwa.ingest_path) + External import mode workaround for duplicate book rows; noted #940/#941 as not-yet-shipped.
Calibre integration: note Bindery Generate button for API key
Calibre integration: add plugin mode, remove drop_folder, update decision tree - Add plugin (HTTP bridge) mode section with architecture diagram, 3 install options (manual GUI, kubectl exec for PVC containers, k8s init-container), K8s service port config, Bindery settings, and failure behaviour table - Remove drop_folder mode (removed in v0.17.0) - Update decision tree: calibredb vs plugin (was calibredb vs drop_folder) - Add links to docs/CALIBRE-PLUGIN.md and bindery-plugins repo
docs: add the seven pages Home.md already links to Home.md links to seven reference pages that did not yet exist — clicking them rendered GitHub's default "create this page?" stub. Fill them in: - Delay-profiles.md — CRUD surface today; scoring layer on the roadmap (#93) - Custom-formats.md — same story (#94); condition schema documented so users can define formats now and have them take effect when the scoring wire-up lands - Notifications.md — generic-webhook model (no built-in Slack/Discord/ntfy adapters); recipes per provider; SSRF policy escape hatch - Reverse-proxy-and-SSO.md — Traefik/Caddy/nginx snippets; ForwardAuth + Authelia/Authentik patterns; how OPDS + scripts bypass SSO cleanly - OPDS.md — endpoint map, auth precedence (api key / session / basic), KOReader/Moon+/Aldiko setup - Calibre-integration.md — the three modes (off / calibredb / drop-folder) with a decision tree and the real per-mode setting keys - Indexer-and-downloader-recipes.md — Newznab/Torznab pattern, SABnzbd + qBittorrent setup, path-remapping, category IDs (7020 / 3030) Every page reflects actual code paths (verified against internal/api, internal/notifier, internal/calibre) rather than Sonarr-style boilerplate. Features that have CRUD APIs but no enforcement layer yet are explicitly flagged as such, with roadmap links.