master-zapier-plan-draft/packages/verae-staff-session/README.md
George Lambert d8efffe8be
Some checks are pending
offline / test (push) Waiting to run
Close the last three UI leftovers: shared staff HTML, cookie domain, stock Swagger label.
verae-staff-ui holds one review template for CS and access-staff.
Staff cookies take STAFF_COOKIE_DOMAIN for a reverse-proxy host.
/docs stays vendor Swagger with an integrator banner only.
2026-09-11 18:22:57 -04:00

1.1 KiB

verae-staff-session

Shared cookie login for CS / sales / accounting / access-staff HTML.

Forgejo: https://git.georgelambert.org/marchon/verae-staff-session

Port :3027. Set STAFF_AUTH=1 on the department servers and STAFF_SESSION_URL=http://127.0.0.1:3027. Cookie host is the browser host (ports share 127.0.0.1). JSON APIs stay open unless you also send x-staff-key.

Default key: STAFF_KEY or ADMIN_KEY or admin-dev-key.

Multiple hostnames

Cookies are host-scoped. On one operator box (127.0.0.1) that is enough. For several DNS names, put one reverse proxy in front and set STAFF_COOKIE_DOMAIN:

server {
  server_name staff.example.com;
  location /session/ { proxy_pass http://127.0.0.1:3027/; }
  location /cs/      { proxy_pass http://127.0.0.1:3011/; }
  location /sales/   { proxy_pass http://127.0.0.1:3012/; }
  location /acct/    { proxy_pass http://127.0.0.1:3013/; }
  location /staff/   { proxy_pass http://127.0.0.1:3025/; }
}
STAFF_COOKIE_DOMAIN=.example.com
STAFF_COOKIE_SECURE=1
STAFF_SESSION_URL=https://staff.example.com/session
STAFF_AUTH=1