Documentation Gap
Endpoint: GET /api/test/is-initialized
Auth: Not required (public)
Handler: handlers.rs → check_is_initialized()
Current Behavior
Returns whether the system has been initialized (i.e., whether the initial admin user has been created):
// Response 200
{ "initialized": true }
On internal error:
// Response 500
{ "error": "Failed to check initialization status: ..." }
Impact
- Low (P2): This is a utility endpoint used by the frontend login/init flow
- It's publicly accessible without authentication, which is a deliberate design choice (the frontend needs to know whether to show the init or login page)
- Not documenting it could lead to confusion about the bootstrapping flow
Suggested Fix
Add a new behavior contract entry:
| ID |
Module |
Behavior |
Verification |
Layer |
Priority |
| AUTH-005 |
初始化检查 |
GET /api/test/is-initialized 无需认证,返回系统是否已初始化。前端用于决定显示 /init 还是 /login 页面 |
200 + {initialized: boolean} / 500 |
Integration |
P2 |
Context
- Discovered during daily documentation review (2026-07-31)
- Related to AUTH-001 (首次设置) — this endpoint is its prerequisite check
Documentation Gap
Endpoint:
GET /api/test/is-initializedAuth: Not required (public)
Handler:
handlers.rs → check_is_initialized()Current Behavior
Returns whether the system has been initialized (i.e., whether the initial admin user has been created):
On internal error:
Impact
Suggested Fix
Add a new behavior contract entry:
{initialized: boolean}/ 500Context