alireza0:s-ui 关闭 API v2 路由重构 PR,令牌管理应放在真实登录之后

在「api: restructure API v2 routes, add token management and e2e tests」PR 中,alireza0 表示重构 API v2 路由会改变既有集成依赖的公开 API,其中一些即使保留旧路由也会破坏(例如 `GET /apiv2/config`、改为 401、未知 action 返回 404),这类改动应放到下个大版本,因此关闭该 PR。另外允许 API 令牌创建新令牌(包括永久令牌)会让短期或泄露的令牌取得长期访问权限,令牌管理应留在真实登录之后。作者欢迎把当前 API 的 e2e 测试与 Windows DB 句柄修复拆成单独的小 PR 再审。

作者原文

Thanks for the work on this.

Restructuring the API v2 routes changes the public API that existing integrations rely on, and some of it breaks even with the legacy routes kept (for example GET /apiv2/config, the switch to 401, and 404 for unknown actions). A change like this belongs in the next major version, so I'm closing this PR.

Also, letting an API token create new tokens, including permanent ones, would let a short-lived or leaked token give itself lasting access. Token management should stay behind a real login.

If you'd like to send the e2e tests for the current API and the Windows DB-handle fix as a separate small PR, I'd be happy to review it.