- /admin login page (public, noindex): password form + signed-in panel that activates the in-page console. Verified in-browser: login -> panel -> the astroagent handle appears on other pages. - Secret-link login: visit /admin/<token> to sign in without a password. adminauth token() validates a bcrypt-hashed token, sets the session, 302s to /admin. nginx routes the token path to PHP. set-admin-token.php generates it. - Password login kept as a fallback. Verified: token link -> session -> console access; bad token -> /admin?e=1. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DoFYZY9gkGPNDqZ7NuEa9a |
||
|---|---|---|
| .. | ||
| 001_create_metrics_placeholder.sql | ||
| 002_create_sp_plugins.sql | ||
| 003_schema_snapshot.sql | ||
| 004_create_cja_projects.sql | ||
| 005_create_cja_contact.sql | ||
| 006_projects_gallery_skills.sql | ||
| 007_create_cja_changelog.sql | ||
| 008_create_cja_admin.sql | ||
| 009_admin_token.sql | ||