feat(security): enforce admin allowlist guard on admin APIs and attach bearer for admin client

This commit is contained in:
Chris
2026-03-30 21:25:57 +08:00
parent fb515c6c44
commit 15eee2fc9a
9 changed files with 80 additions and 4 deletions

View File

@@ -21,3 +21,6 @@ AUTHENTIK_USERINFO_ENDPOINT=
PUBLIC_FRONTEND_ORIGINS=https://member.ose.tw,https://mkt.ose.tw,https://admin.ose.tw
INTERNAL_SHARED_SECRET=CHANGE_ME
ADMIN_ALLOWLIST_EMAILS=
ADMIN_ALLOWLIST_SUBS=
ADMIN_REQUIRED_GROUPS=