Commit graph

3 commits

Author SHA1 Message Date
Brad Groux
793192e6b3 docs: rename Moltbot references to OpenClaw (formerly Clawdbot/Moltbot) 2026-01-29 23:39:11 -06:00
Brad Groux
c250a5a60f docs: final documentation pass for public release
- CONTRIBUTING: fix Node.js prerequisite (20 → 22), fix .env path, add seed docs, expand project structure
- CHANGELOG: move 1.1.0 to Unreleased (matches package.json 1.0.0), add seed data entry, fix link refs
- README: add examples/ and gitignored annotations to architecture tree
- docs/security.md: update Clawdbot reference to Moltbot, fix release date
2026-01-29 15:51:41 -06:00
Brad Groux
3efa474eb0 feat(server): Add authentication & authorization system
- Add auth middleware (server/src/middleware/auth.ts)
  - API key authentication via Bearer token, X-API-Key header, or query param
  - Role-based authorization (admin, agent, read-only)
  - Localhost bypass option for development
  - WebSocket connection authentication

- Update index.ts to integrate auth middleware
  - Apply authenticate middleware to all /api routes
  - Add /api/auth/status endpoint for diagnostics
  - Protect WebSocket connections with token validation
  - Display auth status in startup banner

- Add configuration via environment variables
  - VERITAS_AUTH_ENABLED (default: true)
  - VERITAS_AUTH_LOCALHOST_BYPASS (default: false)
  - VERITAS_ADMIN_KEY for admin access
  - VERITAS_API_KEYS for named keys with roles

- Add comprehensive security documentation (docs/security.md)
- Add .env.example with all auth configuration options

Closes RF-01
2026-01-28 07:37:44 -06:00