Disable Swagger/ReDoc/OpenAPI JSON by default (B-42)

They enumerate the entire API surface, admin endpoints included, to
anyone who requests them. Gate them behind a new ENABLE_API_DOCS
setting (off by default) and update README/docs and BUGS.md/CLAUDE.md
open-bug counts accordingly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-27 15:34:49 +02:00
co-authored by Claude Sonnet 5
parent 4124dc08e6
commit 22e3cfb2be
10 changed files with 72 additions and 20 deletions
+4 -2
View File
@@ -23,8 +23,10 @@ uvicorn app.main:app --reload --port 8123
```
Open `http://127.0.0.1:8123/` for the test UI, `http://127.0.0.1:8123/admin`
for the admin dashboard, `http://127.0.0.1:8123/docs` for the interactive API
docs.
for the admin dashboard. The interactive API docs at `/docs` are disabled by
default (they'd otherwise expose the whole API surface, admin endpoints
included) — set `ENABLE_API_DOCS=true` in `.env` for local development to
enable them.
Or run the whole stack (app + Caddy reverse proxy with automatic TLS) via
Docker: