Updated backend auth settings

This commit is contained in:
sriram
2026-08-12 18:10:25 +05:30
parent ac8cfacbc9
commit b8d93fbbf2
4 changed files with 106 additions and 16 deletions

View File

@@ -53,6 +53,13 @@ AUTH_TOKEN_TTL_MINUTES=720
AUTH_MAX_LOGIN_ATTEMPTS=10
AUTH_LOCKOUT_SECONDS=300
# Local development only: accept ANY password at /api/auth/login. The username
# still picks the role (`admin` -> admin pages, `user` -> user pages), and the
# token issued is a normal one, so every other guard behaves normally. Unlike
# AUTH_ENABLED=false it leaves the login page working - it just stops checking
# the password. Anyone who can reach the port becomes admin: keep it false here.
AUTH_ALLOW_ANY_LOGIN=false
# Machine consumers of api.<domain> - scripts, partner integrations, your own
# backends. Format: name:role:secret, comma-separated, role is admin or user.
# Callers send the secret as an X-API-Key header.