Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cloudflare Access already authenticates requests at the edge, but Twenty still requires a separate password login. This change verifies the signed Access JWT, maps its email to an existing member of one configured workspace, and creates a normal Twenty session through the existing login-token flow. Browser page requests start this exchange automatically and return to the requested page.
Unknown users and users outside the configured workspace receive
403. API requests keep their existing authentication behavior.Validation
Decisions
v2.40.0— a fixed release makes upgrades deliberate and rollback reproducible; do not use the mutablelatesttag./home/sergiy/twentyas its own Compose project — this isolates CRM lifecycle and data from taskmachine; do not add unrelated services to the taskmachine stack.127.0.0.1:3020— the existing Cloudflare Tunnel is the only public path and port 3000 is occupied; do not expose the application on all host interfaces.UserSessionCookieService— it handles both secure and local cookie names from the raw header before session middleware runs; readingrequest.cookieswould redirect valid sessions.