Backend:
- SSE endpoints changed from GET to POST for JWT auth compliance
- Chat subscription moved to /api/room/{room}/chat/subscribe (avoids route conflict)
- handleAuthCheck now returns config:write permission (was missing from response)
Frontend:
- EventSource replaced with fetch POST + Authorization Bearer header
- Token persisted in localStorage, cleared on logout
- postSSE helper with exponential backoff reconnection
- rooms.tsx: SSE/loading gated on can('room:list'), not just isAuthed
- watch.tsx: room events SSE gated on can('room:watch'), chat SSE on can('room:chat')
- watch.tsx: subscribe button disabled when lacking room:subscribe
- permissions.ts: added isPublisher() helper
This commit adds multiple major features and improvements:
1. Add runtime config API with save/reset capabilities
2. Implement per-room distributor override with global fallback
3. Add user management page and inline user controls
4. Update auth policy with admin/root permissions
5. Refine frontend navigation and error boundary
6. Update static assets and build system
7. Add CDN/SRS/Cloudflare config apply logic
Replace the legacy vanilla HTML/CSS/JS pages with a SolidJS single-page
app (TanStack Router/Query, Ark UI, Tailwind v4) and embed its build
output into the Go binary via //go:embed. SPA routes fall back to
index.html. Includes the room chat/danmaku panel, color picker and
broadcaster overlay on the watch/publish pages. Add web/node_modules
and local data to .gitignore.