diligence/backend/app
Claude 5294745704 Fix: replace all settings.algorithm references with hardcoded ALGORITHM
SEC-11 removed algorithm from Settings but missed 3 call sites:
- auth.py line 68: jwt.decode in get_current_user
- integrations.py lines 58, 120: jwt.decode in OAuth callbacks

All now use ALGORITHM constant or inline 'HS256'.
2026-06-22 00:17:58 +00:00
..
models Deliver Steps 3-8: integration config, meal plans, provider registry, MCP connector (14 tools), B2A files, nginx proxy, AGENT_GUIDE, LICENSE 2026-06-15 14:34:09 +00:00
routers Fix: replace all settings.algorithm references with hardcoded ALGORITHM 2026-06-22 00:17:58 +00:00
schemas Stream D: Security hardening — 10 fixes from QA review 2026-06-21 23:13:53 +00:00
services Stream B: Device sync base class + provider registry (already committed) 2026-06-21 23:16:58 +00:00
utils Fix: replace all settings.algorithm references with hardcoded ALGORITHM 2026-06-22 00:17:58 +00:00
__init__.py Initial commit: full fitness-rewards app 2026-03-14 23:53:00 +00:00
config.py Stream D: Security hardening — 10 fixes from QA review 2026-06-21 23:13:53 +00:00
database.py Fix: add future annotations to all files, fix date field name shadowing type in RewardRedeemRequest 2026-03-15 00:42:13 +00:00
main.py Fix: SyntaxError in main.py — comma after allow_credentials=False 2026-06-22 00:08:28 +00:00