- OIDC callback now passes only ?sso=ok flag, token stays in httpOnly cookie (prevents token leaking to logs/referrer/history) - Frontend auth.js uses cookie-based auth for SSO flow - Add [PHYSICIAN TEMPLATES] boundary markers around physicianMemories in all 5 generation routes to mitigate prompt injection - Consistent boundary format across wellVisit, sickVisit, hpi, soap, hospitalCourse |
||
|---|---|---|
| .. | ||
| components | ||
| css | ||
| icons | ||
| js | ||
| vendor | ||
| 404.html | ||
| favicon.ico | ||
| index.html | ||
| manifest.json | ||
| sw.js | ||