- Session manager now calls EncryptID /api/auth/start + /api/auth/complete to get a properly signed JWT instead of creating unsigned local tokens. This fixes 401 errors on /api/payments, /api/notifications, and other authenticated endpoints that verify tokens via EncryptID server. - Token refresh calls /api/session/refresh instead of extending unsigned tokens - Server generateSessionToken now includes authTime, jti, recoveryConfigured - rNetwork: /crm route renders folk-crm-view instead of iframe - rNetwork: ?view=app redirects 301 to /crm (backward compat) - rNetwork: graph viewer always uses API (removed hardcoded demo data) - docker-compose: pass through TWENTY_API_TOKEN from Infisical - rcart: add catalog product images Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| folk-crm-view.ts | ||
| folk-graph-viewer.ts | ||
| network.css | ||