The browser treated sessionStorage as the source of truth for the logged-in user and never verified or invalidated the server-side session cookie: no GET /api/v1/demo/session or POST /api/v1/demo/logout endpoint existed, and a central 401 handler was defined but never wired up. Add both endpoints; the session-check response is marked Cache-Control: no-store to avoid the browser serving a stale "authenticated" response right after logout. AuthProvider now verifies against the server on every mount (sessionStorage only caches presentation state to avoid a login-screen flash), subscribes to a central 401 listener on the API client, and RequireAuth shows a loading state during verification instead of flashing protected content or the wrong role.
40 lines
1.3 KiB
Bash
40 lines
1.3 KiB
Bash
COMPOSE_PROJECT_NAME=mobilityops
|
|
MOBILITYOPS_ENV=development
|
|
MOBILITYOPS_DEMO_MODE=true
|
|
MOBILITYOPS_PUBLIC_URL=http://localhost:1228
|
|
MOBILITYOPS_API_URL=http://localhost:8128
|
|
DATABASE_URL=postgresql+psycopg://mobilityops:mobilityops@db:5432/mobilityops
|
|
POSTGRES_DB=mobilityops
|
|
POSTGRES_USER=mobilityops
|
|
POSTGRES_PASSWORD=mobilityops
|
|
APP_SECRET=replace-in-production
|
|
DEMO_TODAY=2026-08-01
|
|
TZ=Europe/Brussels
|
|
# Session cookie Secure flag. Keep false for LAN/plain-HTTP deployments (including the
|
|
# current Unraid review environment); set true only once MobilityOps is served over HTTPS,
|
|
# otherwise browsers will silently drop the cookie and no one can log in.
|
|
SESSION_COOKIE_SECURE=false
|
|
|
|
# n8n
|
|
N8N_BASE_URL=http://n8n:5678
|
|
N8N_WEBHOOK_URL=http://n8n:5678/webhook/mobilityops-return
|
|
N8N_ENCRYPTION_KEY=replace-me
|
|
N8N_BASIC_AUTH_ACTIVE=true
|
|
N8N_BASIC_AUTH_USER=admin
|
|
N8N_BASIC_AUTH_PASSWORD=change-me
|
|
MOBILITYOPS_CALLBACK_TOKEN=replace-me-n8n-callback-token
|
|
|
|
# RAGcore integration
|
|
KNOWLEDGE_PROVIDER=demo
|
|
RAGCORE_BASE_URL=http://ragcore-api:8000
|
|
RAGCORE_TENANT=northstar-mobility-demo
|
|
RAGCORE_WORKSPACE=mobilityops
|
|
RAGCORE_COLLECTION=internal-procedures
|
|
RAGCORE_API_TOKEN=
|
|
|
|
# ITWorx MCP Hub integration
|
|
MCP_HUB_REGISTRATION_ENABLED=false
|
|
MCP_HUB_BASE_URL=http://itworx-mcp-hub:8000
|
|
MCP_HUB_SERVICE_TOKEN=replace-me-mcp-hub-token
|
|
MCP_PROVIDER_ID=mobilityops
|