Add Auth & Portal Drift Guardrails - forbidden APIv1/Pterodactyl/CSRF/cookie patterns, enforce Portal→JWT→APIv2 flow
This commit is contained in:
parent
bd067ba801
commit
b4f88d2c47
@ -43,3 +43,16 @@ If drift is detected:
|
|||||||
1. Revert the change
|
1. Revert the change
|
||||||
2. Document why it was tempting
|
2. Document why it was tempting
|
||||||
3. Re-apply only what serves usability
|
3. Re-apply only what serves usability
|
||||||
|
|
||||||
|
## Auth & Portal Drift Guardrails
|
||||||
|
|
||||||
|
The following are explicitly disallowed:
|
||||||
|
|
||||||
|
- Reintroducing APIv1 endpoints
|
||||||
|
- Reintroducing Pterodactyl-based auth
|
||||||
|
- CSRF token logic
|
||||||
|
- Cookie-based authentication
|
||||||
|
- Server-side portal sessions
|
||||||
|
|
||||||
|
All auth must flow:
|
||||||
|
Portal → JWT → APIv2
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user