07a3756b18a2c26db091ba6baf61331a4f56f7b3
Mirrors the pattern sitesvc already proves: 32 random bytes, only the SHA-256 hash stored, a 24-hour expiry, and the token cleared on use -- so a leaked database yields no working links. Unverified login returns a distinct "verify your email address first" rather than the generic error. The address is already known to be theirs, so there is nothing to disclose and that is the only useful thing to say. Licence blobs are emailed inline. A blob is signed public data, not a secret: it is useless on any instance other than the one it names. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Description
No description provided
9 MiB
Releases
22
agent/v1.2.13
Latest
Languages
Go
48.5%
TypeScript
47.1%
CSS
2.3%
Go Template
1.3%
Dockerfile
0.5%
Other
0.3%