Commit Graph
8 Commits
Author SHA1 Message Date
greeneclipse 7bafd7a322 fix 2026-08-24 04:03:44 +02:00
greeneclipse 0c154254c3 major fixes 2026-08-22 18:51:17 +02:00
greeneclipseandClaude Fable 5 0eef202f56 Add SESSION_COOKIE_DOMAIN so /admin SSR sees the session cookie
Production splits web (descrybe.io) and API (api.descrybe.io). The session
cookie was host-only for api.descrybe.io, so the browser never sent it to
the web host. The /admin SvelteKit SSR gate (fetchMeStaff in
+layout.server.ts) forwards the incoming cookie header to /api/auth/me —
with no cookie to forward it always got 401 and bounced every successful
login back to /login?next=/admin (login POST 200, /me 200 from the
browser, /me 401 from the web server).

New SESSION_COOKIE_DOMAIN env (default empty = host-only, local dev
unchanged) sets the session cookie Domain attribute; set it to the parent
domain (descrybe.io) in production so both hosts receive the cookie.
Leading dot is normalized away. CSRF needs no change — it already seeds
cross-origin via the X-CSRF-Token response header.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-18 00:31:58 +02:00
greeneclipse 2a2b01bf59 fix 2026-08-17 23:06:07 +02:00
greeneclipse 6fcdc74843 fix 2026-08-17 21:20:45 +02:00
greeneclipse 93dc70123c fix 2026-08-17 00:39:25 +02:00
greeneclipse a9395585f8 fix 2026-08-14 00:06:43 +02:00
greeneclipse 8580c996c3 Initial commit of Descrybe v2 without local scratch artifacts.
Drop one-shot tmp/axe scripts and agent i18n scratch so the Gitea tree is deployable.
2026-08-09 22:47:43 +02:00