Commit Graph
5 Commits
Author SHA1 Message Date
Thanakorn f11af6e949 Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js)
- every library, font and data file served from assets/vendor with pinned
  versions (VERSIONS.json); no CDN at runtime
- Content-Security-Policy on app, sign-in and landing pages
- remove httpbin Dropzone target and source-map references
2026-09-24 14:53:41 +07:00
Thanakorn 234814a23c Seed Demo Data - Rebranding 2026-08-17 13:12:07 +07:00
Thanakorn S 9e200d31fe Security hardening: invited user onboarding flow (C1–N7) 2026-05-26 10:18:40 +07:00
Thanakorn S cf25732da0 use roles guards 2026-05-22 08:45:35 +07:00
Thanakorn S 6eeebfeacb 1) user invitation 2) app access control 3) txn quota guard 2026-05-21 11:42:47 +07:00