Add Basic Auth gate, job owner context, and multi-tenant job isolation.
- Server: auth routes, owner profile on requests/jobs/pipeline, migrations - Client: BasicAuthAppGate, SSE/API session handling, profile quick switch - Tests: tracer-links, ghostwriter request-context mock, pipeline coverage - Env examples for cron and optional basic auth credentials Made-with: Cursor
This commit is contained in:
@@ -22,6 +22,7 @@ MODEL=google/gemini-3-flash-preview
|
||||
# Path is absolute or relative to the orchestrator process cwd (often `orchestrator/` when using `npm run dev` there).
|
||||
# Takes precedence over Settings → local path. PDF export still uses RxResume when enabled.
|
||||
# Example (monorepo): hand-authored v5 JSON may live under `data/resumes/` (that folder is gitignored by default).
|
||||
# If you use seeded search profiles with `resumeLocalPath` + login auto-activate, leave this unset so Settings → local path wins.
|
||||
# JOBOPS_LOCAL_RESUME_PATH=../data/resumes/ilia-dobkin.json
|
||||
|
||||
# RXResume credentials for PDF generation
|
||||
@@ -32,6 +33,14 @@ RXRESUME_PASSWORD=your_password_here
|
||||
# Optional: Basic Auth for write access
|
||||
# the app is fully unauthenticated if this isn't set, which is the default
|
||||
# When set, all write actions (POST/PATCH/DELETE) require Basic Auth.
|
||||
# Optional second user (e.g. paired with a second search profile / `basicAuthUser` in profile JSON):
|
||||
# BASIC_AUTH_USER_2=
|
||||
# BASIC_AUTH_PASSWORD_2=
|
||||
# Example local pairing with DB-seeded profiles (change passwords before exposing the UI):
|
||||
# BASIC_AUTH_USER=ilia
|
||||
# BASIC_AUTH_PASSWORD=changeme-ilia
|
||||
# BASIC_AUTH_USER_2=cherepaha
|
||||
# BASIC_AUTH_PASSWORD_2=changeme-cherepaha
|
||||
BASIC_AUTH_USER=
|
||||
BASIC_AUTH_PASSWORD=
|
||||
|
||||
|
||||
Reference in New Issue
Block a user