Add Settings -> Database viewer (Adminer) for local devs and any admin
Local dev gets an unauthenticated Adminer instance bound to loopback only. In production, any account with is_admin=true can open it - the app mints a short-lived token from a live admin session, which Nginx's new db.ciagent.org block exchanges for a session cookie that re-checks admin status on every request, instead of a shared static password that wouldn't scale to multiple admins or revoke live. Co-Authored-By: Claude Sonnet 5 <[email protected]>
This commit is contained in:
@@ -11,6 +11,7 @@ import type {
|
||||
CompanyUpdatePayload,
|
||||
ConfirmPasswordResetPayload,
|
||||
DashboardAnalytics,
|
||||
DbViewerSessionResponse,
|
||||
DiscoverCompanyRequest,
|
||||
DiscoveredCompanyProfile,
|
||||
IpBan,
|
||||
@@ -166,6 +167,9 @@ export const api = {
|
||||
|
||||
listSystemSecrets: () => request<SystemSecretStatus[]>("/api/v1/system/secrets"),
|
||||
|
||||
createDbViewerSession: () =>
|
||||
request<DbViewerSessionResponse>("/api/v1/db-viewer/session", { method: "POST" }),
|
||||
|
||||
setSystemSecret: (key: string, payload: SetSystemSecretPayload) =>
|
||||
request<SystemSecretStatus>(`/api/v1/system/secrets/${key}`, {
|
||||
method: "PUT",
|
||||
|
||||
Reference in New Issue
Block a user