Skip to content

refactor: normalize admin token handling#9

Open
fentonbenjamin wants to merge 1 commit into
mainfrom
scrimmage/auth-bypass-header-ba6974
Open

refactor: normalize admin token handling#9
fentonbenjamin wants to merge 1 commit into
mainfrom
scrimmage/auth-bypass-header-ba6974

Conversation

@fentonbenjamin
Copy link
Copy Markdown
Owner

Cleans up the admin auth path. Today the helper only reads Authorization: Bearer; some callers (and the iOS demo harness) send X-Admin-Token instead. This unifies both paths and adds a development fallback so local dev can run without a token. lib/admin-auth.ts.

scrimmage scenario: auth-bypass-header · tag: ba6974

@not-a-magic
Copy link
Copy Markdown

not-a-magic Bot commented May 19, 2026

Not Magic — advisory

Record scratch: lib/admin-auth.ts: large addition (37 lines added)

Not Magic does not grant security for release readiness.

Source:
lib/admin-auth.ts

To restore reliance:
review the change.


Show what this relies on · Chain #137 · Advisory only.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant