feat: close the panel behind gnexus-auth (OAuth PKCE)
Auth off by default (client_id empty). When GHARD_AUTH_CLIENT_ID is set,
the web UI gets a creds-style sign-in gate: splash -> /me -> login screen
(OAuth starts from the click, not page load). Sessions and OAuth state
live in SQLite (survive restarts); webhook endpoint applies global_logout/
profile updates. Scripts/MCP keep working with the Bearer token, agents
keep X-Server-Key ingest. Includes compose env passthrough, README guide.

Co-Authored-By: Claude Code <noreply@anthropic.com>
1 parent 9625022 commit f52c85352b21a6fb6e3469c8006ab46748c49621
@Eugene Sukhodolskiy Eugene Sukhodolskiy authored 9 hours ago
Showing 13 changed files
View
README.md
View
docker-compose.yml
View
panel/backend/.env.example
View
panel/backend/Dockerfile
View
panel/backend/app/api/auth_routes.py 0 → 100644
View
panel/backend/app/auth.py 0 → 100644
View
panel/backend/app/config.py
View
panel/backend/app/main.py
View
panel/backend/app/schema.sql
View
panel/backend/app/security.py
View
panel/backend/pyproject.toml
View
panel/frontend/src/App.vue
View
panel/frontend/src/api.js