mirror of
https://github.com/hansjone/netx.git
synced 2026-10-10 06:10:47 +08:00
Harden auth with revocable sessions, cookies, and single-login default.
Issue short-lived access JWTs backed by AuthSession rows, HttpOnly cookies with refresh rotation, idle timeout, session management UI, WebCRT ownership caps, and optional Redis login rate limits; new logins revoke other sessions by default. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
ba33ab5c4f
commit
20c2fcd496
34 changed files with 1462 additions and 149 deletions
|
|
@ -54,6 +54,9 @@ const AuditPage = lazy(() => import("./pages/AuditPage").then((m) => ({ default:
|
|||
const ApiTokensPage = lazy(() =>
|
||||
import("./pages/ApiTokensPage").then((m) => ({ default: m.ApiTokensPage })),
|
||||
);
|
||||
const SessionsPage = lazy(() =>
|
||||
import("./pages/SessionsPage").then((m) => ({ default: m.SessionsPage })),
|
||||
);
|
||||
|
||||
/** Preserve query when redirecting legacy /network/webcrt → /webcrt. */
|
||||
function NetworkWebcrtRedirect() {
|
||||
|
|
@ -129,6 +132,7 @@ function ProtectedApp() {
|
|||
<Route path="logs" element={<AuditPage />} />
|
||||
</Route>
|
||||
<Route path="/api-keys" element={<ApiTokensPage />} />
|
||||
<Route path="/sessions" element={<SessionsPage />} />
|
||||
<Route path="*" element={<Navigate to="/" replace />} />
|
||||
</Routes>
|
||||
</Suspense>
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue