- Add VERSION = "1.1.0" to server.py; print at startup, expose via public
GET /api/config, and show it in the admin header (so deployed == released
is verifiable at a glance).
- Ignore config.json in .gitignore — it holds the admin password hash and
session secret; fresh installs use config.json.example.
- README/CLAUDE.md: document the in-app pixel editor (now with shape tools,
select/move, reference overlay, custom/recent palettes), the receiver health
dashboard, 9 sprite types, and the asset cache-busting convention.
- Bump admin asset cache-bust to ?v=20260609d.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Implements credentialed admin panel and multi-step setup wizard so new
users can configure location, receivers, and preferences without editing
JSON files. Adds bcrypt password auth with session cookies, setup lockout
after first run, and expanded config schema with backward compatibility.
New files: admin/{html,css,js}, setup/{html,css,js}
Modified: server.py (auth, setup, admin APIs), index.html (dynamic title),
pixel-view.js (site/display config), requirements.txt (bcrypt),
config.json.example (full schema)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>