- /admin/projects list + /admin/projects/edit gallery editor (AdminLayout chrome,
session-guarded). Upload/replace images per slot, captions, add/remove,
Instagram reel URL. Save -> cja_projects -> rebuild -> live.
- adminprojects API (list/get/save); media path validation (local paths only).
- runner /rebuild endpoint: build public/ + commit after structured edits.
- Ownership: app/ + public/ now owned by carlos-arias-agent:caweb so the agent
can rebuild its own output; www serves via the caweb group. Documented in
SETUP.md — never build as root.
Verified end to end: upload image -> save to gallery -> rebuild -> image live on
the project page and served.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoFYZY9gkGPNDqZ7NuEa9a
- /admin login page (public, noindex): password form + signed-in panel that
activates the in-page console. Verified in-browser: login -> panel -> the
astroagent handle appears on other pages.
- Secret-link login: visit /admin/<token> to sign in without a password.
adminauth token() validates a bcrypt-hashed token, sets the session, 302s to
/admin. nginx routes the token path to PHP. set-admin-token.php generates it.
- Password login kept as a fallback.
Verified: token link -> session -> console access; bad token -> /admin?e=1.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoFYZY9gkGPNDqZ7NuEa9a