Updated backend auth settings
This commit is contained in:
@@ -53,6 +53,13 @@ AUTH_TOKEN_TTL_MINUTES=720
|
||||
AUTH_MAX_LOGIN_ATTEMPTS=10
|
||||
AUTH_LOCKOUT_SECONDS=300
|
||||
|
||||
# Local development only: accept ANY password at /api/auth/login. The username
|
||||
# still picks the role (`admin` -> admin pages, `user` -> user pages), and the
|
||||
# token issued is a normal one, so every other guard behaves normally. Unlike
|
||||
# AUTH_ENABLED=false it leaves the login page working - it just stops checking
|
||||
# the password. Anyone who can reach the port becomes admin: keep it false here.
|
||||
AUTH_ALLOW_ANY_LOGIN=false
|
||||
|
||||
# Machine consumers of api.<domain> - scripts, partner integrations, your own
|
||||
# backends. Format: name:role:secret, comma-separated, role is admin or user.
|
||||
# Callers send the secret as an X-API-Key header.
|
||||
|
||||
Reference in New Issue
Block a user