diff --git a/config/initializers/devise_token_auth.rb b/config/initializers/devise_token_auth.rb index bb64943..f0997ce 100644 --- a/config/initializers/devise_token_auth.rb +++ b/config/initializers/devise_token_auth.rb @@ -48,5 +48,6 @@ DeviseTokenAuth.setup do |config| # do so by enabling this flag. NOTE: This feature is highly experimental! # config.enable_standard_devise_support = false + config.bypass_sign_in = false config.default_confirm_success_url = 'https://turnie.re' end diff --git a/doc/rails_8_dependency_update.md b/doc/rails_8_dependency_update.md index e0c2ec3..d67bc1f 100644 --- a/doc/rails_8_dependency_update.md +++ b/doc/rails_8_dependency_update.md @@ -9,6 +9,12 @@ The project no longer uses the Thor77 `devise_token_auth` fork. The released gem currently supports this stack through `devise_token_auth` 1.2.6 with `devise` 4.9.4. +Because this is an API-only app without session middleware, +`DeviseTokenAuth.bypass_sign_in` must stay disabled. With the gem default +enabled, authenticated token requests call Devise session bypass code and fail +in API-only production. Disabled mode still authenticates token requests with +`store: false`. + ## Docker Versioning Container versioning still uses the shared pipeline `base_commit` build arg.