admin and Claude Sonnet 4.6
0e479b648f
fix(auth,capa): restore auth callback, fix CAPA status update
...
- auth callback: remove debug redirect, handle both code (PKCE) and
token_hash+type (recovery/magic link) flows correctly
- capa PATCH: use admin client to bypass RLS for status updates
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01WMymkhHZiaYZtUeH9MEHZQ
2026-07-22 19:43:38 +08:00
admin and Claude Sonnet 4.6
e682162bbc
fix(auth): redirect to appUrl after invite callback
...
origin lacks /ims basePath; use NEXT_PUBLIC_APP_URL instead.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01BzvzV91UqHZKM9P58qtvrA
2026-07-16 21:44:12 +08:00
admin
1879def32c
security: P0 fixes — IDOR on incident/CAPA, CAPA non-owner write, timing-safe recheck cron, auth callback open redirect
2026-07-12 20:36:28 +08:00
admin and Claude Sonnet 4.6
559859470b
feat: add login page and auth callback route
...
- Replace default Next.js home with role-aware root redirect
- Add email/password login form (client component, signInWithPassword)
- Add auth callback route for Supabase code exchange
- Login page at /login, callback at /api/auth/callback
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01AWxyMibCuGGtSQSqfajDQ7
2026-07-09 22:18:21 +08:00