- stop exposing the raw Pico token to the frontend - add /api/pico/info for non-secret Pico connection metadata - proxy /pico/ws through the launcher with same-origin and dashboard auth checks - inject the upstream Pico websocket protocol server-side - update frontend chat connection flow and Vite websocket proxy path - refresh related docs and tests |
||
|---|---|---|
| .. | ||
| access_control.go | ||
| access_control_test.go | ||
| launcher_dashboard_auth.go | ||
| launcher_dashboard_auth_test.go | ||
| middleware.go | ||
| referrer_policy.go | ||