Gitea sendet das Webhook-Secret als HMAC-SHA256-Signatur des Bodys, nicht als
Klartext-Header. Bisher liefen alle per Secret konfigurierten Repo-Hooks auf
401 - Push-Deploys funktionierten nur ueber ?token= in der URL.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sichert den bisher uncommitteten Produktionsstand des Kundenbereich-Servers,
damit kuenftige Deploys (git reset --hard) nichts mehr verwerfen.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Express-Server für Appwrite-Auth, Session, Projekt-Dashboard und Gitea-Webhook; statisches Frontend und Schema-Dokumentation für woms-database.
Co-authored-by: Cursor <cursoragent@cursor.com>