fix: remove session bootstrap frontend config from compose

Per reviewer feedback: exposing SKILLHUB_WEB_AUTH_SESSION_BOOTSTRAP_* in the
compose without matching SKILLHUB_AUTH_SESSION_BOOTSTRAP_ENABLED on the server
would cause 403 errors when frontend attempts bootstrap.

Keep this PR focused on direct auth only. Bootstrap variables are still handled
in 30-runtime-config.sh with false defaults, so runtime-config.js will have
authSessionBootstrapEnabled: "false" and frontend will not trigger bootstrap.
This commit is contained in:
Caffrey 2026-04-13 14:31:26 +08:00 • committed by wowo-zZ
parent e81a70542e
commit 7ea44b1b11

View file

@ -117,9 +117,6 @@ services:
SKILLHUB_PUBLIC_BASE_URL: ${SKILLHUB_PUBLIC_BASE_URL:-}
SKILLHUB_WEB_AUTH_DIRECT_ENABLED: ${SKILLHUB_WEB_AUTH_DIRECT_ENABLED:-false}
SKILLHUB_WEB_AUTH_DIRECT_PROVIDER: ${SKILLHUB_WEB_AUTH_DIRECT_PROVIDER:-}
SKILLHUB_WEB_AUTH_SESSION_BOOTSTRAP_ENABLED: ${SKILLHUB_WEB_AUTH_SESSION_BOOTSTRAP_ENABLED:-false}
SKILLHUB_WEB_AUTH_SESSION_BOOTSTRAP_PROVIDER: ${SKILLHUB_WEB_AUTH_SESSION_BOOTSTRAP_PROVIDER:-}
SKILLHUB_WEB_AUTH_SESSION_BOOTSTRAP_AUTO: ${SKILLHUB_WEB_AUTH_SESSION_BOOTSTRAP_AUTO:-false}
depends_on:
server:
condition: service_healthy