You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add admin login/logout and auth proxy
Introduces a simple session-based admin auth flow and middleware to protect the app.
- Adds POST /api/auth/login: validates the provided password against ADMIN_PASSWORD, sets an httpOnly `stash_session` cookie (HMAC-SHA256 hex of a fixed nonce) on success, returns 403 on invalid credentials and 500 if ADMIN_PASSWORD is not configured.
- Adds POST /api/auth/logout: clears the `stash_session` cookie.
- Adds a client-side login page at /login with form, loading/error states, and navigation on success.
- Adds a proxy middleware (web/src/proxy.ts) that redirects unauthenticated requests to /login, skips static assets and public routes (/login, /api/auth/login, /api/auth/logout), and treats missing ADMIN_PASSWORD as open access.
- Updates Navbar to include a logout button that calls the logout endpoint and navigates to the login page.
This provides basic admin protection for the app; session tokens are derived from the admin password using an HMAC-based scheme and stored in a cookie with Lax sameSite and a 7-day expiry.