fix: derive JWT iat from server clock

Shaarli rejects tokens whose iat falls outside its clock
tolerance, so device/server skew caused HTTP 401 logins
even with a correct API secret. Estimate server time from
the Date response header, retry a 401 once with a
recalibrated token, trim credentials on login, and explain
the API-secret vs password mismatch in French error
messages.

Bump version to 2.14.1 (code 42).
This commit is contained in:
2026-10-07 16:33:24 -04:00
parent 40944a9a55
commit 8f90d5b3b8
6 changed files with 146 additions and 18 deletions
+2 -2
View File
@@ -1,3 +1,3 @@
#Thu Apr 23 19:46:44 2026
VERSION_NAME=2.14.0
VERSION_CODE=41
VERSION_NAME=2.14.1
VERSION_CODE=42