Commit Graph

5 Commits

Author SHA1 Message Date
Paddy 7ce42324da Sign in through the admin app instead of this one
The frontend half of the calendar auth cutover (step 4 of
docs/calendar-auth-migration.md in the API repo). This app now shares one
identity with the tickets, feedback and admin apps.

Every call carries the session cookie via withCredentials rather than
appending sessionId/sessionKey to the URL, so there is no credential left in
api.service.ts at all - that was DEFERRED_SECURITY.md item 1.

The login and registration forms are gone. Accounts exist only by invitation
from the admin app, so both were one redirect; sign-out ends the session for
all four apps and returns here, so doing it by accident costs one click.

401 and 403 are deliberately not collapsed. Only 401 goes to the login page:
redirecting on 403 produces a loop where signing in succeeds and lands
straight back on the refusal, and doing it for an unreachable API produces the
same loop with no way out. Both of those now render a message instead.

src/app/models/session.ts and the unrouted LoginComponent are dead but left in
place; removing files is a separate decision.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-06 22:23:45 +02:00
Paddy 55748260d0 Claude init file + div. improvements 2026-05-02 14:29:23 +02:00
Paddy 9ed6f9968e Upgrade to proper user management
Jenkins Production Deployment
2023-05-14 21:08:55 +02:00
Paddy 8ae121ca0c Finish edit capabilities and add adding capabilities 2022-12-26 15:59:24 +01:00
Paddy 6822bb8a04 Add components 2022-12-25 17:48:24 +01:00