mirror of
https://github.com/BradGroux/veritas-kanban.git
synced 2026-10-11 06:07:54 +00:00
- Add auth middleware (server/src/middleware/auth.ts) - API key authentication via Bearer token, X-API-Key header, or query param - Role-based authorization (admin, agent, read-only) - Localhost bypass option for development - WebSocket connection authentication - Update index.ts to integrate auth middleware - Apply authenticate middleware to all /api routes - Add /api/auth/status endpoint for diagnostics - Protect WebSocket connections with token validation - Display auth status in startup banner - Add configuration via environment variables - VERITAS_AUTH_ENABLED (default: true) - VERITAS_AUTH_LOCALHOST_BYPASS (default: false) - VERITAS_ADMIN_KEY for admin access - VERITAS_API_KEYS for named keys with roles - Add comprehensive security documentation (docs/security.md) - Add .env.example with all auth configuration options Closes RF-01 |
||
|---|---|---|
| .. | ||
| security.md | ||
| settings-architecture.md | ||
| sprint-1.md | ||
| sprint-2.md | ||
| sprint-3.md | ||
| sprint-4.md | ||
| sprint-5.md | ||
| sprint-6.md | ||
| sprint-7.md | ||
| sprint-8.md | ||
| sprint-9.md | ||
| sprint-10.md | ||
| sprint-12.md | ||
| sprint-13.md | ||
| sprint-14.md | ||