docs: reconcile [Unreleased] with full git history since 1.2.5
test / test (push) Has been cancelled

Expand the doc-alignment entry to cover guide RBAC and restore Resync
wording; trim the P2 entry of claims superseded by that pass while keeping
its /license route-table addition with a cross-reference.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-08-14 19:40:46 +03:00
parent 1bd71c10d0
commit e9aaed1c7b
+13 -11
View File
@@ -87,12 +87,14 @@ Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); version
- docs: operator and as-built docs aligned with the code after a full - docs: operator and as-built docs aligned with the code after a full
pass — [architecture.md](docs/architecture.md) route table now marks pass — [architecture.md](docs/architecture.md) route table now marks
**global** routes (404 for domain administrators) and documents the **global** routes (404 for domain administrators) and documents the
one-time restore Resync; session/password and restore-session wording one-time restore Resync in Persistence; session/password and restore-session
corrected in [guide.md](docs/guide.md) and architecture (own-password change wording corrected in [guide.md](docs/guide.md) and architecture (own-password
vs admin reset, no "logout everywhere", immediate session restore, PTR cache change vs admin reset, no "logout everywhere", immediate session restore on
≈1 min, decrypt has no version check); [README.md](README.md) port-587 and the next request, PTR cache ≈1 min, decrypt has no version check, restore
quick-start volume wording fixed; [security.md](docs/security.md) CSRF ADR Resync on first boot, domain add/delete/import and `POST /reload` global-only,
points at `authz.go` for route gating. No behaviour change. Settings DMARC global-only); [README.md](README.md) port-587 and quick-start
volume wording fixed; [security.md](docs/security.md) CSRF ADR points at
`authz.go` for route gating. No behaviour change.
- docs: [guide.md](docs/guide.md) reorganised into **Installation**, **Instance - docs: [guide.md](docs/guide.md) reorganised into **Installation**, **Instance
administration**, and **Domain administration** — DNS setup, operations, administration**, and **Domain administration** — DNS setup, operations,
@@ -188,11 +190,11 @@ Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); version
check defends against, and gives a new revisit trigger. Dropped the check defends against, and gives a new revisit trigger. Dropped the
unimplemented "or argon2" alternative for the password hash. unimplemented "or argon2" alternative for the password hash.
[guide.md](docs/guide.md) documents the Users page and the two roles, [guide.md](docs/guide.md) documents the Users page and the two roles,
the Settings page's default DMARC report address, level-2 rate limiting's level-2 rate limiting's fail-open behaviour, and that a domain-admin can
fail-open behaviour, that restoring an older backup can resurrect sessions, export working SASL passwords for domains assigned to them.
and that a domain-admin can export working SASL passwords for domains [architecture.md](docs/architecture.md) gains `/license` and the
assigned to them. [architecture.md](docs/architecture.md)'s route table now `/account``/settings` redirect in the route table (later expanded for
lists `/license` and the `/account``/settings` redirect. Corrected stale RBAC in the doc-alignment pass above). Corrected stale
`admin.dmarc_report_email` references in `admin.dmarc_report_email` references in
[roadmap.md](docs/roadmap.md) and [roadmap.md](docs/roadmap.md) and
[docs/plans/dmarc-reports.md](docs/plans/dmarc-reports.md) to the setting's [docs/plans/dmarc-reports.md](docs/plans/dmarc-reports.md) to the setting's