Add Auth & Portal Drift Guardrails - forbidden APIv1/Pterodactyl/CSRF/cookie patterns, enforce Portal→JWT→APIv2 flow

This commit is contained in:
jester 2025-12-28 22:28:40 +00:00
parent bd067ba801
commit b4f88d2c47

View File

@ -42,4 +42,17 @@ If no, remove it.
If drift is detected: If drift is detected:
1. Revert the change 1. Revert the change
2. Document why it was tempting 2. Document why it was tempting
3. Re-apply only what serves usability 3. Re-apply only what serves usability
## Auth & Portal Drift Guardrails
The following are explicitly disallowed:
- Reintroducing APIv1 endpoints
- Reintroducing Pterodactyl-based auth
- CSRF token logic
- Cookie-based authentication
- Server-side portal sessions
All auth must flow:
Portal → JWT → APIv2