e1306dab6976148c5f9259a54d10a5610cfc5767
- Validates JWT with verifySigningToken(); returns expired/invalid/used/pending - Checks signingTokens.usedAt for one-time-use enforcement - Logs link_opened + document_viewed audit events on valid pending access - Extracts IP from x-forwarded-for/x-real-ip headers for audit trail - Public route — no auth() import or session required
Description
No description provided
Languages
TypeScript
97.5%
Shell
1.6%
Dockerfile
0.4%
JavaScript
0.3%
CSS
0.2%