Attribution comes from the proxy's basic-auth username, which nginx already forwards. Recorded as a ledger of billed calls rather than a column on the grade: a regrade overwrites the grade row, so a per-row cost would forget what earlier runs cost, and deleting a card would erase that it was ever paid for. Splits server-key spend (money the host actually owes) from own-key spend (billed to the visitor) — the two must never be summed. Attribution only, never authorization: the app is reachable directly on the LAN, so these headers are not trustworthy for access control. |
||
|---|---|---|
| .. | ||
| app.js | ||
| icon-180.png | ||
| icon-192.png | ||
| icon-512-maskable.png | ||
| icon-512.png | ||
| icon.svg | ||
| index.html | ||
| manifest.json | ||
| style.css | ||
| sw.js | ||