Restore ume_verify_tls=false so onsite UME login works without a .env override; production should set NETX_UME_VERIFY_TLS=true or pin a CA.
Co-authored-by: Cursor <cursoragent@cursor.com>
Point .env.example at NETX_UME_VERIFY_TLS=false for self-signed UME and surface the same hint on certificate verify login failures.
Co-authored-by: Cursor <cursoragent@cursor.com>
Use DELETE delete-subscription, refresh token before cancel, recover orphan subs on establish, and keep local state when UME delete fails.
Co-authored-by: Cursor <cursoragent@cursor.com>
Non-reentrant Lock caused /v1/ume/token/refresh to hang when handshake failed or token empty inside renew; UI stuck on 续期中.
Co-authored-by: Cursor <cursoragent@cursor.com>
Previously exp>mem_exp blocked loading when both were 0 (restart + DB row with missing expiry). Also clear in-memory token when DB row is cleared so token/status matches store after disconnect.
Co-authored-by: Cursor <cursoragent@cursor.com>