docs: update documentation, add future tasks, and fix debug endpoint security
- **Documentation Overhaul**: - **README.md**: Restructured installation guide to align with Nextcloud 33+ paths (e.g., "Personal Settings → Security"), added curl examples, updated known limitations, and added a "Future Features" section. - **agent.md**: Updated architecture documentation to reflect `TalkService.php` growth (1138 to 1904 lines), updated constructor parameters, and corrected method documentation (e.g., `buildRichObject` now creates TYPE_ROOM shares, `postToRoom` uses query params). - **architecture.md**: Added notes regarding the admin gate for the debug endpoint. - **New Files**: - Added `Future to-do.md` to track planned features (inbound messages, filtering, etc.). - Added `TODO.md` to track pending tasks and code cleanup. - **Code Fixes**: - **lib/Controller/WebhookController.php**: Re-applied `#[AdminRequired]` attribute to the `debug()` method to enforce admin authentication. - **lib/Service/TalkService.php**: Updated docblock for `buildRichObject` to clarify it creates TYPE_ROOM shares. - **lib/Settings/Admin.php** & **templates/adminSettings.php**: Corrected bot password generation instructions to point to the correct Nextcloud settings path. - **Configuration**: - **appinfo/info.xml**: Bumped version to 1.2.1 and updated `max-version` to 35.
This commit is contained in:
@@ -295,6 +295,8 @@ The `/debug` endpoint exposes sensitive data (DB schema, bot credentials, config
|
||||
- Enabled only via CLI (`php occ nc_bot_webhooks:debug:enable`)
|
||||
- Stored in `appconfig` (not hardcoded)
|
||||
- Documented with explicit warnings
|
||||
- **Admin gate required** — accessible only to admin users when enabled.
|
||||
- **TODO: add auto-disable timer (2h TTL) to prevent accidental prolonged exposure.**
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user