feat(10-01): harden the admin cookie session and prefix boot guards
- refresh and logout read the Bearer header first, then the summer_admin cookie; a cookie refresh rotates the cookie without a token in the body and logout always expires the cookie - backend.cookie_secure (default true) may drop Secure outside production only - activation rejects controller vendor segments api, assets, login, settings - BuildRouter rejects non-cabana routes at or under the admin prefix - SPA single-flights refresh on 401, replays once, and refreshes proactively at 80 percent of expires_in; dist rebuilt - scripts/check-admin-dist.sh rebuilds the SPA and fails on dist drift - tests: TestPhase10CookieAuth, TestPhase10CSRF, TestPhase10Prefix, TestPhase10AdminPrefixCollision, boardwalk serving and header tests
This commit is contained in:
1
boardwalk/dist/assets/index-BD2QIjGC.js
vendored
Normal file
1
boardwalk/dist/assets/index-BD2QIjGC.js
vendored
Normal file
File diff suppressed because one or more lines are too long
1
boardwalk/dist/assets/index-ZNCn30hM.js
vendored
1
boardwalk/dist/assets/index-ZNCn30hM.js
vendored
File diff suppressed because one or more lines are too long
2
boardwalk/dist/index.html
vendored
2
boardwalk/dist/index.html
vendored
@@ -6,7 +6,7 @@
|
||||
<meta name="robots" content="noindex, nofollow" />
|
||||
<meta name="summer-admin-base" content="__SUMMER_ADMIN_BASE__" />
|
||||
<title>SummerCMS</title>
|
||||
<script type="module" crossorigin src="./assets/index-ZNCn30hM.js"></script>
|
||||
<script type="module" crossorigin src="./assets/index-BD2QIjGC.js"></script>
|
||||
<link rel="stylesheet" crossorigin href="./assets/index-UTAit0wB.css">
|
||||
</head>
|
||||
<body>
|
||||
|
||||
Reference in New Issue
Block a user