Brad Groux
|
c250a5a60f
|
docs: final documentation pass for public release
- CONTRIBUTING: fix Node.js prerequisite (20 → 22), fix .env path, add seed docs, expand project structure
- CHANGELOG: move 1.1.0 to Unreleased (matches package.json 1.0.0), add seed data entry, fix link refs
- README: add examples/ and gitignored annotations to architecture tree
- docs/security.md: update Clawdbot reference to Moltbot, fix release date
|
2026-01-29 15:51:41 -06:00 |
|
Brad Groux
|
3efa474eb0
|
feat(server): Add authentication & authorization system
- Add auth middleware (server/src/middleware/auth.ts)
- API key authentication via Bearer token, X-API-Key header, or query param
- Role-based authorization (admin, agent, read-only)
- Localhost bypass option for development
- WebSocket connection authentication
- Update index.ts to integrate auth middleware
- Apply authenticate middleware to all /api routes
- Add /api/auth/status endpoint for diagnostics
- Protect WebSocket connections with token validation
- Display auth status in startup banner
- Add configuration via environment variables
- VERITAS_AUTH_ENABLED (default: true)
- VERITAS_AUTH_LOCALHOST_BYPASS (default: false)
- VERITAS_ADMIN_KEY for admin access
- VERITAS_API_KEYS for named keys with roles
- Add comprehensive security documentation (docs/security.md)
- Add .env.example with all auth configuration options
Closes RF-01
|
2026-01-28 07:37:44 -06:00 |
|