admin and Claude Sonnet 4.6
4fbab33de4
fix(auth): add forgot/reset to public routes, use Link for basePath, add session guard
...
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01WMymkhHZiaYZtUeH9MEHZQ
2026-07-21 22:36:53 +08:00
admin and Claude Sonnet 4.6
8061f804f7
feat: self-service change password for all roles
...
- middleware.ts: add /account to isSharedRoute so all roles can reach it
- components/account/change-password-form.tsx: re-auth with current password
then updateUser({password}) with client-side validation (length, match, diff)
- app/(protected)/account/page.tsx: dedicated account page, no role gate
- sidebar.tsx: Account link (all roles) above Logout in desktop footer
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01CPf5Rc8QPx6V8KLEEgfKEQ
2026-07-12 22:17:51 +08:00
admin
c80091c8d6
security: CAPA privilege escalation, CSV injection, AI rate-limit, prompt injection guard, open redirect, timing-safe cron secret, server-only admin client, notifications RLS
2026-07-12 17:33:58 +08:00
admin
580a60bbd8
fix: admin role bypasses path prefix guard — can access all protected routes
2026-07-12 15:03:56 +08:00
admin
706a075d73
fix: use nextUrl.clone() for middleware redirects to preserve basePath /ims
2026-07-12 14:39:01 +08:00
admin
c1c874b3fe
fix: exclude /api/cron from auth middleware so cron jobs run unauthenticated
2026-07-12 13:59:54 +08:00
admin
3f8da5bd91
feat: incident report form, API route, middleware shared-route + redirect
2026-07-10 13:19:45 +08:00
admin
28957f1e0f
fix: patch critical auth and RLS security findings from final review
2026-07-10 06:01:36 +08:00
admin and Claude Sonnet 4.6
6939a21183
feat: add user role types and auth middleware
...
- lib/auth/roles.ts: UserRole union, ALL_ROLES, ROLE_HOME, getRoleHome, isValidRole (pure, no Supabase imports)
- __tests__/lib/auth/roles.test.ts: 8 TDD tests (written before implementation)
- middleware.ts: createServerClient with request.cookies pattern, unauthenticated redirect to /login, role-based redirect on / and /login
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01AWxyMibCuGGtSQSqfajDQ7
2026-07-09 21:39:32 +08:00