Skip to content

History / Authentication

Revisions

  • docs(auth): document CCG admin privilege restriction Service accounts using client credentials grant cannot use administrator privileges; admin operations require PKCE. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

    @ericfitz ericfitz committed Apr 15, 2026
  • docs: add comprehensive Authentication wiki page New page covering PKCE and CCG OAuth flows with mermaid sequence diagrams, JWT token delivery models (HttpOnly cookies vs Bearer), browser security (CORS, SameSite, CSP), WebSocket ticket-based auth with origin checking, and proxy/TLS requirements. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

    @ericfitz ericfitz committed Apr 5, 2026