feat(auth) : add admin account management
CI / Verify (push) Successful in 57s
CI / Build immutable images and deploy (push) Successful in 2m7s

This commit is contained in:
2026-09-04 10:54:08 +07:00 Unverified
parent 53b79cc7e8
commit a865913a08
15 changed files with 3703 additions and 245 deletions
+4 -8
View File
@@ -20,7 +20,7 @@ Production target: `https://guide.sudloh.com`
- Restricted decimal formula engine with named references, dependency ordering,
cycle detection, typed failures, and presentation-only rounding.
- Read-only comparison charts with visible values and accessible table fallbacks.
- Better Auth email/password login restricted to the configured `ADMIN_EMAIL`.
- Better Auth email/password login with administrator-managed accounts.
- Private S3-compatible media uploads with reference-aware same-origin delivery.
- PostgreSQL transactions, immutable data-source versions, revisions, and a
retryable outbox.
@@ -39,7 +39,7 @@ formula fixtures. Their guide text and media are not imported or published.
| `/[character]` | Redirect to the first visible page |
| `/[character]/[page]` | Render a public guide page |
| `/admin/login` | Administrator email/password sign-in |
| `/register` | Temporary administrator account bootstrap |
| `/admin/register` | Create and remove administrator accounts |
| `/admin` | Character and page overview |
| `/admin/[character]/[page]` | Visual page editor |
| `/admin/create` | Create a structured guide from the synced character catalog |
@@ -68,11 +68,8 @@ cp .env.example .env
`.env.example` contains placeholders only. Configure `.env` yourself; it is
ignored by Git and must never be committed. `BETTER_AUTH_URL` must exactly
match the application origin. Visit `/register` once to create the credential
account using an address listed in `ADMIN_EMAIL`, then use `/admin/login` for
later access. Separate multiple administrator addresses with commas. The
registration endpoint rejects every other email; remove the temporary page
after the administrator account has been created.
match the application origin. Existing administrators can create additional
credential accounts from `/admin/register`; public registration is disabled.
Prepare the database and start the application:
@@ -216,7 +213,6 @@ Before the first rollout, a cluster administrator must provision a
```text
DATABASE_URL
BETTER_AUTH_SECRET
ADMIN_EMAIL
REDIS_URL
S3_ENDPOINT
S3_PUBLIC_URL