ppt-tool/frontend/app/api
Vadym Samoilenko 864278a0fa Comprehensive audit: fix auth, basePath, security, and UI bugs
Backend security (P0):
- Add get_current_user auth to all files endpoints (upload, decompose, url, update)
- Add get_current_user auth to all images endpoints (generate, upload, uploaded, generated, delete)
- Add get_current_user auth to slide edit and edit-html endpoints
- Add get_current_user auth to outlines SSE stream endpoint (was fully unauthenticated)

Frontend API fixes:
- adminSlice fetchTeams: bare fetch() → apiFetch() (was missing basePath prefix)
- dashboard getPresentation: add missing getHeader() auth headers
- images getUploadedImages/deleteImage: add missing getHeader() auth headers
- templates/[id] toggle layout: bare fetch() → apiFetch() (404 in production)
- header.ts: remove incorrect client-side CORS headers (Access-Control-Allow-*)

UI fixes:
- admin/users: add fetchUsers() refetch after deactivate (table wasn't updating)
- presentationGeneration.ts: fix corrupt comment with embedded import statement

Security:
- has-required-key/route.ts: remove console.log() leaking OPENAI_API_KEY to logs

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-20 18:46:45 +00:00
..
can-change-keys Phase 1-2: Foundation + Admin Panel & Client Management 2026-02-26 15:37:17 +00:00
export-as-pdf Phase 5: Fix export, slide edit, static files; add README 2026-02-27 15:40:36 +00:00
generate-pptx Add 3 sandbox features: diagrams, mermaid, and template code-gen 2026-03-19 18:47:31 +00:00
has-required-key Comprehensive audit: fix auth, basePath, security, and UI bugs 2026-03-20 18:46:45 +00:00
mermaid-to-image Add 3 sandbox features: diagrams, mermaid, and template code-gen 2026-03-19 18:47:31 +00:00
presentation_to_pptx_model Phase 5: Fix export, slide edit, static files; add README 2026-02-27 15:40:36 +00:00
read-file Phase 1-2: Foundation + Admin Panel & Client Management 2026-02-26 15:37:17 +00:00
save-layout Phase 1-2: Foundation + Admin Panel & Client Management 2026-02-26 15:37:17 +00:00
telemetry-status Phase 1-2: Foundation + Admin Panel & Client Management 2026-02-26 15:37:17 +00:00
template Phase 1-2: Foundation + Admin Panel & Client Management 2026-02-26 15:37:17 +00:00
templates Phase 1-2: Foundation + Admin Panel & Client Management 2026-02-26 15:37:17 +00:00
upload-image Phase 1-2: Foundation + Admin Panel & Client Management 2026-02-26 15:37:17 +00:00
user-config Phase 1-2: Foundation + Admin Panel & Client Management 2026-02-26 15:37:17 +00:00
v1/ppt Fix SSE proxy: create Next.js route handlers for all streaming endpoints 2026-03-01 20:43:58 +00:00