Add API keys / bearer tokens for forward auth
Some checks failed
Some checks failed
Enables server-to-server authentication for forward auth applications (e.g., video players accessing WebDAV) where browser cookies aren't available. API keys use clk_ prefixed tokens stored as HMAC hashes. Bearer token auth is checked before cookie auth in /api/verify. Invalid tokens return 401 JSON (no redirect). Requests without bearer tokens fall through to existing cookie flow unchanged. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -40,6 +40,8 @@ Rails.application.routes.draw do
|
||||
end
|
||||
|
||||
# Authenticated routes
|
||||
resources :api_keys, only: [:index, :new, :create, :show, :destroy]
|
||||
|
||||
root "dashboard#index"
|
||||
resource :profile, only: [:show, :update] do
|
||||
member do
|
||||
|
||||
Reference in New Issue
Block a user