b40464632c6aa47e2938a61d09735e004636deb6
Add MUSIC_APP_ORIGIN to the origin allowlist and a global originScopeMiddleware that restricts scoped app origins (the standalone officer-music client) to their permitted path prefixes — /api/auth and /api/music — and 403s everything else. The main web origin is unaffected, and the gate no-ops while MUSIC_APP_ORIGIN is unset. Lets extra sign-in-only users authenticate through the music app and reach only music + auth, without reintroducing any per-user permission scheme. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Description
No description provided
42 MiB
Languages
TypeScript
90.9%
Shell
4.7%
JavaScript
4.1%
CSS
0.2%
HTML
0.1%