lahirujayathilake opened a new pull request, #498:
URL: https://github.com/apache/airavata-custos/pull/498

   The portal moves from a dev-credentials sign-in to a real OIDC login and 
forwards the verified bearer token on every backend call.
   
   - Single OIDC provider in NextAuth, configured via env.
   - Sign-in page collapsed to one button.
   - The proxy at `/api/v1/*` attaches `Authorization: Bearer …` and drops the 
legacy `x-custos-user-id` fallback header.
   - The admin proxy path (`/api/v1/admin/*`) now requires an authenticated 
session plus the `roles:manage` privilege; anonymous access is rejected.
   - Privileges are fetched from the backend at sign-in time and cached on the 
session JWT so the server-side portal gate sees them.
   - Generated portal API client regenerated from the BearerAuth OpenAPI spec.
   
   Note - This `auth-endpoints-web` branch changes depends on the changes 
shipped with `auth-endpoints`. Therefore the PR points to that branch to 
clearly show the changes. I'll update the target branch to master once the 
`auth-endpoints` changes are merged into the `master` branch.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to