Application boundary#
These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.
Verified routes#
GET/audit⌄
Audit page.
- Authentication
- session + administrator role
- Permission
- no separate permission identifier in handler (admin/owner/runtime checks as above)
- Request body
- none
- Query parameters
- none explicitly read
- Headers
- none beyond shared session/CSRF
- Response structure
HTML template response (handler names the template)- Important errors
- none literal; shared/helper errors apply
- Approval behavior
- no standalone approval behavior in this handler.
Verified route registration · handler audit_page. Some definitions may be partially redacted; no missing fields are inferred.
DELETE/api/audit⌄
Audit clear.
- Authentication
- session + administrator role
- Permission
- no separate permission identifier in handler (admin/owner/runtime checks as above)
- Request body
- none
- Query parameters
- none explicitly read
- Headers
- none beyond shared session/CSRF
- Response structure
{ok, deleted}- Important errors
- none literal; shared/helper errors apply
- Approval behavior
- no standalone approval behavior in this handler.
Verified route registration · handler api_audit_clear. Some definitions may be partially redacted; no missing fields are inferred.
Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.