Backend:
- SSE endpoints changed from GET to POST for JWT auth compliance
- Chat subscription moved to /api/room/{room}/chat/subscribe (avoids route conflict)
- handleAuthCheck now returns config:write permission (was missing from response)
Frontend:
- EventSource replaced with fetch POST + Authorization Bearer header
- Token persisted in localStorage, cleared on logout
- postSSE helper with exponential backoff reconnection
- rooms.tsx: SSE/loading gated on can('room:list'), not just isAuthed
- watch.tsx: room events SSE gated on can('room:watch'), chat SSE on can('room:chat')
- watch.tsx: subscribe button disabled when lacking room:subscribe
- permissions.ts: added isPublisher() helper
|
||
|---|---|---|
| .. | ||
| data | ||
| src | ||
| index.html | ||
| package.json | ||
| pnpm-lock.yaml | ||
| tsconfig.json | ||
| vite.config.ts | ||