seedproject-web/api/cli
Carlos Arias b967419717 Phase 1: admin login page + secret-link token auth
- /admin login page (public, noindex): password form + signed-in panel that
  activates the in-page console. Verified in-browser: login -> panel -> the
  astroagent handle appears on other pages.
- Secret-link login: visit /admin/<token> to sign in without a password.
  adminauth token() validates a bcrypt-hashed token, sets the session, 302s to
  /admin. nginx routes the token path to PHP. set-admin-token.php generates it.
- Password login kept as a fallback.

Verified: token link -> session -> console access; bad token -> /admin?e=1.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DoFYZY9gkGPNDqZ7NuEa9a
2026-07-23 22:15:50 +00:00
..
rebuild.php feat: user auth (email + Google OAuth), Mailer, and CLI bridges 2026-07-11 09:14:25 -05:00
resources.php feat: user auth (email + Google OAuth), Mailer, and CLI bridges 2026-07-11 09:14:25 -05:00
seed-changelog.php Baseline: full site build (brand, pages, DB, agent-editable) 2026-07-23 20:21:28 +00:00
seed-projects.php Baseline: full site build (brand, pages, DB, agent-editable) 2026-07-23 20:21:28 +00:00
set-admin-password.php Phase 0: admin console foundation 2026-07-23 20:23:48 +00:00
set-admin-token.php Phase 1: admin login page + secret-link token auth 2026-07-23 22:15:50 +00:00