Disable Swagger/ReDoc/OpenAPI JSON by default (B-42)

They enumerate the entire API surface, admin endpoints included, to
anyone who requests them. Gate them behind a new ENABLE_API_DOCS
setting (off by default) and update README/docs and BUGS.md/CLAUDE.md
open-bug counts accordingly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-27 15:34:49 +02:00
co-authored by Claude Sonnet 5
parent 4124dc08e6
commit 22e3cfb2be
10 changed files with 72 additions and 20 deletions
+3
View File
@@ -12,6 +12,9 @@ uvicorn app.main:app --reload --port 8123
- App su `http://127.0.0.1:8123/`
- Pannello admin su `http://127.0.0.1:8123/admin`
- Docs API interattive su `http://127.0.0.1:8123/docs` solo se `ENABLE_API_DOCS=true`
in `.env` — disattivate di default perché espongono l'intera API, endpoint
admin inclusi (vedi [setup.md](setup.md))
- Log applicativi in `logs/app.log` (rotante, 10MB × 5 backup)
- Nessun TLS, nessun reverse proxy — solo per test locali sulla tua macchina.