Plant acht stories ST-1001..ST-1008 voor password-loze inlog via QR-pairing. Mobiele bevestiging met UA+IP, demo-blokkade, paired-sessie 8u TTL. Security-uitgangspunt: mobileSecret reist alleen via QR-fragment + POST-body, desktop-SSE/claim via HttpOnly pre-auth cookie — geheim materiaal nooit in URL-paden, querystrings, access logs of browsergeschiedenis. Twee gescheiden hashes in DB (secret_hash + desktop_token_hash). Bouwt voort op M8 LISTEN/NOTIFY- infra met eigen channel scrum4me_pairing. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| patterns | ||
| plans | ||
| agent-instruction-audit.md | ||
| API.md | ||
| erd.svg | ||
| icons.html | ||
| MD3_Color_Scheme_Documentation.md | ||
| scrum4me-architecture.md | ||
| scrum4me-backlog.md | ||
| scrum4me-functional-spec.md | ||
| scrum4me-personas.md | ||
| scrum4me-product-backlog.md | ||
| scrum4me-styling.md | ||
| scrum4me-test-plan.md | ||
| solo-paneel-spec.md | ||