|
feat: close the panel behind gnexus-auth (OAuth PKCE)
Auth off by default (client_id empty). When GHARD_AUTH_CLIENT_ID is set, the web UI gets a creds-style sign-in gate: splash -> /me -> login screen (OAuth starts from the click, not page load). Sessions and OAuth state live in SQLite (survive restarts); webhook endpoint applies global_logout/ profile updates. Scripts/MCP keep working with the Bearer token, agents keep X-Server-Key ingest. Includes compose env passthrough, README guide. Co-Authored-By: Claude Code <noreply@anthropic.com> |
|---|
|
|
| README.md |
|---|
| docker-compose.yml |
|---|
| panel/backend/.env.example |
|---|
| panel/backend/Dockerfile |
|---|
| panel/backend/app/api/auth_routes.py 0 → 100644 |
|---|
| panel/backend/app/auth.py 0 → 100644 |
|---|
| panel/backend/app/config.py |
|---|
| panel/backend/app/main.py |
|---|
| panel/backend/app/schema.sql |
|---|
| panel/backend/app/security.py |
|---|
| panel/backend/pyproject.toml |
|---|
| panel/frontend/src/App.vue |
|---|
| panel/frontend/src/api.js |
|---|