baton/backend
Gros Frumos 0562cb4e47 sec: server-side email domain check + IP block on violations
Only @tutlot.com emails allowed for registration (checked server-side,
invisible to frontend inspect). Wrong domain → scary message + IP
violation tracked. 5 violations → IP permanently blocked from login
and registration. Block screen with OK button on frontend.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-21 15:58:16 +02:00
..
__init__.py kin: BATON-002 [Research] UX Designer 2026-03-20 20:44:00 +02:00
config.py kin: BATON-BIZ-001-backend_dev 2026-03-21 13:49:57 +02:00
db.py sec: server-side email domain check + IP block on violations 2026-03-21 15:58:16 +02:00
main.py sec: server-side email domain check + IP block on violations 2026-03-21 15:58:16 +02:00
middleware.py sec: server-side email domain check + IP block on violations 2026-03-21 15:58:16 +02:00
models.py auth: replace UUID-based login with JWT credential verification 2026-03-21 14:14:12 +02:00
push.py kin: BATON-008-backend_dev 2026-03-21 09:19:50 +02:00
telegram.py feat: geo location as Google Maps link in Telegram notifications 2026-03-21 14:21:41 +02:00