b5e155fb72
Categories can now be marked "Private" in the admin panel's Category priority list. Private categories (and every article tagged with one, even if it's also tagged with a public category) are hidden from /api/categories, /api/feed, and /api/article/:id for anyone without a valid login — a plain visitor's browser, not the admin API key, since that's a header-based credential for the admin SPA only. Login is a single shared password set via PRIVATE_ACCESS_PASSWORD in the backend's .env (unset by default, which disables the feature entirely). On success the backend sets a stateless httpOnly cookie — its value is a deterministic hash of the password, checked with a timing-safe comparison on every request, so there's no session table to maintain. The cookie is requested at the ~400-day cap browsers enforce on persistent cookies, the closest a cookie can get to "retained indefinitely." On the frontend, an always-visible lock icon in the masthead (shown whenever the feature is configured, independent of the admin panel's own enabled/disabled toggle) opens a password prompt and reflects locked/unlocked state. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014c1L8ghNBFjfiH64UMViP8