You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PR #8 added the identity foundation: GitHub OAuth sign-in plus a per-session login + role (developer/admin), with the role enforced at the proxy/API layer (app/src/proxy.ts gates /api/admin, /api/settings, /api/ingest, /api/audit-log for role=admin). Consuming the role in the UI was explicitly out of scope for that PR.
Problem
In identity mode, the Settings page still shows the shared-password admin prompt. AdminGate (app/src/components/auth/admin-gate.tsx) calls GET /api/auth/verify-admin, which returns required based solely on whether ADMIN_PASSWORD is set — it has no awareness of the identity role. So an identity admin is still prompted for the admin password, which is redundant (the proxy already enforces role=admin on the underlying /api/settings/* calls).
Proposed follow-up
Identity-aware admin gate — in identity mode, an identity admin (role=admin) skips the password prompt; a developer is denied (no password fallback). Suggested touch points: app/src/app/api/auth/verify-admin/route.ts (consider the identity session + resolveRole) and app/src/components/auth/admin-gate.tsx.
Nav gating — hide/disable the Settings nav entry for non-admin identity users.
Background
PR #8 added the identity foundation: GitHub OAuth sign-in plus a per-session
login+role(developer/admin), with the role enforced at the proxy/API layer (app/src/proxy.tsgates/api/admin,/api/settings,/api/ingest,/api/audit-logforrole=admin). Consuming the role in the UI was explicitly out of scope for that PR.Problem
In identity mode, the Settings page still shows the shared-password admin prompt.
AdminGate(app/src/components/auth/admin-gate.tsx) callsGET /api/auth/verify-admin, which returnsrequiredbased solely on whetherADMIN_PASSWORDis set — it has no awareness of the identityrole. So an identity admin is still prompted for the admin password, which is redundant (the proxy already enforcesrole=adminon the underlying/api/settings/*calls).Proposed follow-up
role=admin) skips the password prompt; adeveloperis denied (no password fallback). Suggested touch points:app/src/app/api/auth/verify-admin/route.ts(consider the identity session +resolveRole) andapp/src/components/auth/admin-gate.tsx.Keep changes additive so open/shared-password modes are unaffected.
Refs: #8