Two authentication models
The tool has two groups of routes. They do not share an authentication method.httpOnly, Secure and SameSite=Lax. Its Path is set explicitly.
Status codes
The codes carry meaning. A client must treat them differently.401 and 410 are separate answers on purpose. A client that treats them as one either retries a dead session forever or throws away a good token.Reviewer routes
These routes use the bearer token.Session
A session response carries the session, the project, the author, the whitelist, the anchor algorithm versions and the upload limits.
Threads and comments
Uploads
Admin routes
These routes use the gateway session cookie. The account also needs thewebpage-review flag.
Projects
Whitelist
Reviewer sessions
A token lasts 7, 14, 30 or 90 days. The default is 30 days.
Threads, uploads and read state
Identifiers
Every{id} matches this pattern.
Sizes
The system uses 1024 × 1024 for one megabyte, everywhere. The conversion from a typed megabyte figure to bytes happens one time, in the router.The two readings of a megabyte differ by 4.9 percent at 1000 MB. Nobody would notice which one shipped. For that reason the choice is made in one place and written down.