Security and production
Keep secrets server-side
OAuth client secrets, JWT_SECRET, database credentials and GitHub credentials belong in the Bunny Edge Function environment. Never commit them, place them in VITE_* variables or include them in a browser URL.
The API exchanges OAuth callbacks through a short-lived one-time code. Refresh sessions use Secure HttpOnly cookies, and provider credentials are stored server-side.
Browser access and permissions
Set ALLOWED_ORIGINS to the exact web origins that may call the API. Include the protocol and port where relevant; do not include a path.
Project membership and role are enforced by the API. Editors are restricted to content paths. Administrator-only operations include project credentials, schema/scaffold changes, invites and merges.
Before production
- Apply the current database schema, including OAuth state and authorization-code tables.
- Set
WEB_APP_URL,FUNCTION_URLandALLOWED_ORIGINS. - Test GitHub and Google OAuth over HTTPS.
- Verify editor and administrator access with separate accounts.
- Confirm that preview and production origins are not mixed.