mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 19:21:33 +02:00
get_stored_token() reads the global Settings rows when auth is disabled and User.cloud_token when it is enabled, so completing /auth/setup switched which store the /cloud/* routes consult without moving the token. An account linked before enabling auth was stranded: build_authenticated_cloud() returned None, get_filament_info() skipped its cloud phase and answered 200 from local fallbacks, and /cloud/devices began returning 401 -- all silently. setup_auth() now migrates the global token onto the owning admin and deletes the global rows; disable_auth() mirrors the hand-off back. Neither guesses: setup migrates only when it creates the admin or exactly one exists, disable declines to overwrite an existing global token. Region survives both hops. Instances that already crossed the transition must re-link once.