Commit Graph
6 Commits
Author SHA1 Message Date
maziggy 42b07d8bfd Add API key auth support to /auth/me for SpoolBuddy kiosk
When Bambuddy auth is enabled, the SpoolBuddy kiosk gets redirected to
the login page because ProtectedRoute requires a user from GET /auth/me,
which only handled JWT tokens. The kiosk daemon already has an API key
but couldn't use it to satisfy the frontend auth check.

- Backend: /auth/me now accepts API keys (Bearer bb_xxx or X-API-Key)
  and returns a synthetic admin UserResponse with all permissions
- Frontend: AuthContext reads ?token= from URL on first load, stores in
  localStorage, and strips from URL (prevents history/referrer leakage)
- Install script: kiosk URL now includes ?token=${API_KEY}
- Tests: 3 new integration tests (Bearer API key, X-API-Key header,
  invalid key rejection)
2026-02-27 13:34:19 +01:00
maziggy cc13166fea Updated Spoolbuddy install script 2026-02-27 13:33:47 +01:00
maziggy f7e65aa8e3 Updated Spoolbuddy install script to strip down Raspbian 2026-02-27 13:33:47 +01:00
maziggy 414dc4a511 Updated RPI install script 2026-02-23 11:34:43 +01:00
maziggy eba4184097 Updated RPI install script 2026-02-23 11:29:17 +01:00
maziggy 851b039dd8 Added Spoolbuddy RPI install script 2026-02-23 10:30:48 +01:00