Add local username/password login as fallback when Microsoft login isn't available
Build and Deploy / version (push) Successful in 1s
Build and Deploy / build (push) Successful in 21s
Build and Deploy / deploy (push) Successful in 1s

Neues "users"-Table (bcrypt-Hash, nie Klartext), POST /api/auth/login gibt ein
selbst-signiertes JWT (HS256) aus. requireAuth unterscheidet MSAL- (RS256) und
lokale Tokens (HS256) anhand des alg-Headers. Server legt beim Start optional
ein erstes lokales Konto an, wenn SEED_ADMIN_USERNAME/SEED_ADMIN_PASSWORD als
Stack-Env gesetzt sind (idempotent, Klartext-Passwort landet nie im Repo).

Frontend: Login-Screen hat jetzt einen Alternativ-Link zu Benutzername/Passwort,
App.tsx kombiniert MSAL- und lokalen Auth-Status.

Temporärer test-build-only.yml Workflow zur Docker-Build-Verifikation ohne
Registry-Push (wird nach dem Test wieder entfernt).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Fidelis Huber
2026-08-21 17:56:40 +02:00
co-authored by Claude Sonnet 5
parent 7bdf4f2897
commit 97c4aa1c68
14 changed files with 263 additions and 32 deletions
+12
View File
@@ -0,0 +1,12 @@
name: Test Build Only (temporary, no push)
on:
workflow_dispatch:
jobs:
build:
runs-on: linux
steps:
- uses: actions/checkout@v4
- name: Docker build (no push)
run: docker build -t materialschein-test:local .