Member invites, gallery resync, content and operator docs

- Invite flow: admin issue/revoke on join requests, public single-use
  claim links (hash-only tokens, 7-day expiry, no state reveal), claim
  creates the Member account and marks the request accepted
- Gallery: admin status page plus resync endpoint; sync refreshes
  thumbnails whose content changed; tools/gallery contract and checker
- Docs: public content page, admin-only operator runbook, api.md
  invite/gallery sections, all routes in the live API docs, docs
  reachability gate test
- Screenshots cover the new pages; version 1.0.18
This commit is contained in:
2026-10-06 02:56:08 +02:00
parent e512556703
commit 9fb4d65787
36 changed files with 1147 additions and 19 deletions
+2 -1
View File
@@ -57,7 +57,7 @@ NOTIFICATION_TYPES = {
"system.maintenance": "Maintenance mode changed",
}
CRAWLER_PRIVATE_PREFIXES = ("/notifications", "/admin", "/profile")
CRAWLER_PRIVATE_PREFIXES = ("/notifications", "/admin", "/profile", "/invite")
CRAWLER_MARKERS = (
"bot",
@@ -94,6 +94,7 @@ SETTINGS_DEFAULTS = {
"rate_limit_window_seconds": "60",
"session_max_age_days": "7",
"session_remember_days": "30",
"invite_expiry_days": "7",
"terms_version": "1",
"friendly_404": "1",
"audit_retention_days": "365",