Shows raw login HTTP code, all response headers, X-CSRF-Token extraction
(header + cookie file fallback), login response body, cookie file contents,
and a follow-up stat/voucher GET to verify the full auth+API flow.
https://claude.ai/code/session_01UsuvFAmmeagtQa14QA4iaq
Move form action identifiers to hidden inputs (add_site, edit_site) so
the server-side isset() check always succeeds regardless of button state.
Pattern matches index.php (create_voucher hidden input).
Update JS loading-state selectors to match new button IDs.
https://claude.ai/code/session_01UsuvFAmmeagtQa14QA4iaq
- Login: replace fragile unique_id/email check with proper HTTP 200 trust +
explicit meta.rc=error detection (matches Art-of-WiFi reference impl)
- Login: add TOKEN cookie fallback for CSRF token extraction in case
the X-CSRF-Token response header is absent (some firmware versions)
- getVouchers(): pass explicit 'GET' method instead of relying on cURL default
- apiRequest(): use CURLOPT_HTTPGET for GET requests; send CURLOPT_POSTFIELDS
as empty object for POST with no data; CSRF header only on non-GET requests
- Remove array_filter() header construction, replace with clean conditional append
https://claude.ai/code/session_01UsuvFAmmeagtQa14QA4iaq
Bug fixes:
- UniFiController: add CURLOPT_TIMEOUT (10s) and CURLOPT_CONNECTTIMEOUT (5s)
to login() and apiRequest() — prevents page freeze when controller unreachable
- UniFiController: fix login response validation for UniFi OS API which returns
a user object instead of meta.rc=ok
- admin/sites.php: add JS loading state on form submit to give visual feedback
- login.php: handle new 'rate_limited' return value from Auth::login()
New features:
- Database: in-memory settings cache eliminates redundant DB queries per request
- Auth: login rate limiting (10 attempts per 10 min per IP/email) via login_attempts table
- admin/vouchers.php: CSV export with UTF-8 BOM for Excel compatibility
- admin/vouchers.php: client-side pagination (50 per page)
- index.php: QR code display after voucher creation (qrcodejs CDN)
- Mailer: sendTestEmail() method
- admin/settings.php: SMTP test button with AJAX handler
- database.sql: add login_attempts and audit_log tables
Readme: condensed from ~420 to ~220 lines, removed duplicated sections,
M365 Azure Portal walkthrough, contribution guidelines, update/migration section
https://claude.ai/code/session_01UsuvFAmmeagtQa14QA4iaq
- Update login endpoint: /api/login → /api/auth/login
- Add X-CSRF-Token extraction via CURLOPT_HEADERFUNCTION in login()
- Inject X-CSRF-Token header into all POST requests in apiRequest()
- Prefix all API paths with /proxy/network (createVoucher, getVouchers, deleteVoucher)
- Update admin/sites.php placeholder and help text to reflect port 11443
- Update Readme.md: fix GitHub clone URL, update port references, rewrite
API documentation section for UniFi OS, add UniFi OS troubleshooting entry,
bump version to 2.1.0
https://claude.ai/code/session_01UsuvFAmmeagtQa14QA4iaq