net/http answered "OPTIONS *" itself, with 200, before the router, so
it skipped the credential check and the security headers. The server
now passes it to the router, which refuses it with 401 like any other
request without the credential. A test sends it to a running server,
since the handler alone never sees it.
Model: opus-5-5
docs/REPO_POLICIES.md requires a Permissions-Policy header restricting
the browser features an application does not use. The API now denies
the camera, microphone and location on every response, TestHeaders
checks it, and the README's Design section names it.
Model: opus-5-5
The bot now serves an HTTP API on PORT (default 8080) beside the chat
client. Every request needs the credential read at startup from the
file named by API_TOKEN_FILE, sent as a bearer token; without one,
every request is refused. Responses carry the security headers, bodies
are capped at 64 KiB and each request's work at 10 seconds.
GET /api/v1/chats lists the bot's contacts from the chat client's
/_contacts command, ordered by id, and marks the contacts who deleted
their chat with the bot, which the chat client keeps listing. bot.Run
starts the API after set-up and stops it within 5 seconds; a listener
failure ends the bot as a chat client failure does.
Model: opus-5-5