|
tests / pest (push) Successful in 7m2s
Details
tests / assets (push) Successful in 20s
Details
tests / release (push) Successful in 3s
Details
The gate exempts admin/* so the console keeps working, but /admin sends a guest to /login and /login is not the console — so with the site hidden and no VPN yet, an operator cannot sign in to flip the switch back. Found while bringing up the live server. The mechanism for it already exists and is the right one: TRUSTED_RANGES. What does NOT work is exempting the login flow by hostname, which was the obvious patch — a Host header is chosen by the caller, so one forged header would have lifted the gate for every route, portal included. Codex caught that; the comment now says why the narrow-looking option is the wrong one. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Controllers | ||
| Middleware | ||