corentin_wakdo/docs
Imugiii 92731c8b59
All checks were successful
CI / secret-scan (push) Successful in 10s
CI / php-lint (push) Successful in 23s
CI / secret-scan (pull_request) Successful in 9s
CI / php-lint (pull_request) Successful in 19s
CI / static-tests (push) Successful in 33s
CI / static-tests (pull_request) Successful in 32s
CI / auto-merge (push) Has been skipped
CI / auto-merge (pull_request) Successful in 4s
fix(admin): remove stale unauthenticated static admin mockups
Les 6 pages .html du back-office (dashboard, users, catalogue, commandes,
cuisine, login) etaient des maquettes statiques de la demo de mai, restees
dans le docroot du vhost admin. Apache les servait telles quelles
(RewriteCond !-f -> pas de reecriture vers index.php), donc HORS SessionGuard :
information disclosure (structure du back-office, libelles, page utilisateurs)
accessible sans authentification, en contradiction avec la posture
security-by-design.

Elles sont superseded par les pages PHP rendues serveur et gardees (P3 :
/admin/dashboard, /admin/categories, /admin/products, /admin/profile/pin).
Les maquettes ne se liaient qu'entre elles (ilot mort) : aucun lien entrant
cote PHP/JS/CSS. La ligne d'exemple de docs/api/conventions.md qui citait
login.html est corrigee (assets/ servis tels quels).
2026-06-16 10:08:41 +00:00
..
_ref docs: add RNCP 37805 referentiel and fix Cr 4.f mappings 2026-04-24 15:27:06 +00:00
api fix(admin): remove stale unauthenticated static admin mockups 2026-06-16 10:08:41 +00:00
architecture P1 conception: security-by-design layer (Merise 21 entities, Forgejo CI/CD, hardening) (#3) 2026-06-15 12:16:11 +02:00
design chore(assets): import school source data and normalize visual assets 2026-04-30 12:43:14 +00:00
journal feat(admin): throttle du PIN d action sensible par acteur (RG-T22) (#18) 2026-06-16 00:06:33 +02:00
merise feat(admin): throttle du PIN d action sensible par acteur (RG-T22) (#18) 2026-06-16 00:06:33 +02:00
uml docs: clarify manager has read-only user access (user.read), not zero access 2026-06-15 13:47:58 +00:00
PROJECT_CONTEXT.md docs: clarify manager has read-only user access (user.read), not zero access 2026-06-15 13:47:58 +00:00