Disable token auth session bypass

This commit is contained in:
Daniel Schädler 2026-04-29 00:06:59 +02:00
parent 7461ae27aa
commit 08070fb87b
2 changed files with 7 additions and 0 deletions

View File

@ -48,5 +48,6 @@ DeviseTokenAuth.setup do |config|
# do so by enabling this flag. NOTE: This feature is highly experimental! # do so by enabling this flag. NOTE: This feature is highly experimental!
# config.enable_standard_devise_support = false # config.enable_standard_devise_support = false
config.bypass_sign_in = false
config.default_confirm_success_url = 'https://turnie.re' config.default_confirm_success_url = 'https://turnie.re'
end end

View File

@ -9,6 +9,12 @@ The project no longer uses the Thor77 `devise_token_auth` fork. The released
gem currently supports this stack through `devise_token_auth` 1.2.6 with gem currently supports this stack through `devise_token_auth` 1.2.6 with
`devise` 4.9.4. `devise` 4.9.4.
Because this is an API-only app without session middleware,
`DeviseTokenAuth.bypass_sign_in` must stay disabled. With the gem default
enabled, authenticated token requests call Devise session bypass code and fail
in API-only production. Disabled mode still authenticates token requests with
`store: false`.
## Docker Versioning ## Docker Versioning
Container versioning still uses the shared pipeline `base_commit` build arg. Container versioning still uses the shared pipeline `base_commit` build arg.