chart/app/api
Chris Amow 7590d53b13 Put diagnostic capture retrieval behind the same auth as everything else
Uploading a capture required a token; retrieving one did not. That was a
deliberate capability-URL design with a test asserting it, and the reasoning
held: it lets whoever is debugging fetch a capture without the chart password.

Changed because of what a capture contains. getDisplayMedia returns a picture of
someone's screen, and preferCurrentTab is a preference rather than a constraint,
so a mis-click shares a different window. An unguessable id stops guessing but
not leakage: capability URLs escape through proxy logs, browser history and
pasted links.

Retrieval now uses the dependency the rest of the API uses, which already
accepts the session cookie — so a logged-in browser needs nothing extra, which
was the condition for making this change at all. An agent on the server reads
the capture directory directly; one working over HTTP sends the API token.

Both handlers moved from meta.py to routes.py. meta.py is the deliberately open
router — health, version, login, logout — and a screenshot endpoint did not
belong there. The existing test now asserts 401 without credentials, and a new
one covers the browser path: log in, then retrieve with only the cookie.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 17:24:04 -05:00
..
__init__.py Implement M1 live one-minute chart 2026-08-09 20:38:50 -05:00
captures.py diagnostic capture feature 2026-08-11 16:08:32 -05:00
deps.py - Drag a selected trendline body to reposition the entire line. 2026-08-11 05:46:09 -05:00
meta.py Put diagnostic capture retrieval behind the same auth as everything else 2026-08-11 17:24:04 -05:00
routes.py Put diagnostic capture retrieval behind the same auth as everything else 2026-08-11 17:24:04 -05:00
schwab_auth.py Add the OAuth callback endpoint at /api/qt 2026-08-10 04:45:31 -05:00
ws.py - Drag a selected trendline body to reposition the entire line. 2026-08-11 05:46:09 -05:00