fix: enable dependency uploads without login #63
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Before the auth implementation, uploading a dependency file didn't require login. This behavior is also described in
project-prd.md
underUS-002
, with no mention of authentication.Current state:

The auth PR introduced
PUBLIC_PATHS
, but it looks like theupload-dependencies
endpoint was missed. This PR fixes that by marking it as public - no login required.If uploading dependencies should require login, then we should either:
If we agree this endpoint should stay public, then this PR is good to go 🟢.
I haven’t added any
RATE_LIMIT_CONFIG
for this endpoint. If you think we should add something lightweight (e.g. 1 upload every 5 seconds), let me know and I’ll include it.Br,
Kacper
Roadmap alignment
Type of change
How Has This Been Tested?
Please describe the tests that you ran to verify your changes.