Moved the restricted-api iframe src to /auth/api/restricted and removed the endpoint of the other restricted app.

This commit is contained in:
Leo Vasanko
2025-12-02 18:34:59 +00:00
parent 3441a7a2b3
commit 2a5f06d707
6 changed files with 14 additions and 17 deletions
+2 -1
View File
@@ -41,7 +41,6 @@ Notes:
| GET | `/auth/` | `/` | Main authentication SPA (non-auth hosts show an account summary view) |
| GET | `/auth/admin/` | `/admin/` | Admin SPA root |
| GET | `/auth/{reset_token}` | `/{reset_token}` | Reset / device addition SPA (token validated) |
| GET | `/auth/restricted` | `/restricted` | Restricted / permission denied SPA |
## Core API (Unrestricted available on all hosts)
@@ -49,6 +48,8 @@ Always under `/auth/api/` (even on auth host):
| Method | Path | Description |
|--------|------|-------------|
| GET | `/auth/api/restricted` | Authentication UI for iframe embedding (supports `?mode=login` or `?mode=reauth`) |
|--------|------|-------------|
| POST | `/auth/api/validate` | Validate & (conditionally) renew session |
| GET | `/auth/api/forward` | Auth proxy endpoint for reverse proxies (204 or 4xx) |
| POST | `/auth/api/set-session` | Set cookie from Bearer token |