## Summary
This release adds authentication, role-based access control, and production deployment configuration for Supabase Cloud.
### Auth system
- Supabase-based authentication with email/password login and signup
- JWT verification middleware on the backend
- Frontend auth flow with login, signup, session management, and auth callback pages
- `ProtectedRoute` and `AdminRoute` components for frontend route protection
- Auth-aware navigation (different links for logged-out, logged-in, and admin users)
### Role-based access control
- `is_admin` column on users table with Alembic migration
- `require_admin` FastAPI dependency protecting admin write endpoints (games, pokemon, evolutions, bosses, routes CRUD)
- Run ownership and visibility (public/private/unlisted)
### Production deployment
- Supabase Cloud auth config in `docker-compose.prod.yml` and `Dockerfile.prod`
- Deploy workflow writes `.env` from Gitea secrets (no manual `.env` on server)
- Frontend build args for Vite to inline Supabase config at build time
### Other changes
- Boss pokemon details (abilities, items, moves)
- Boss result team snapshots
- Moves and abilities API
- User account integration and profile API
- Local GoTrue container for dev auth testing
- Dependency updates (Node 25, Postgres 18, Vite 8, jsdom 29, plugin-react v6, pyjwt 2.12.1, upload-artifact v7)
## Test plan
- [x] All 252 backend tests pass
- [x] All 118 frontend tests pass
- [x] Verify Supabase secrets are configured in Gitea
- [x] Verify Supabase dashboard URL configuration is set
- [x] Deploy and smoke test auth flow end-to-end
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Add user authentication with login/signup/protected routes, boss pokemon
detail fields and result team tracking, moves and abilities selector
components and API, run ownership and visibility controls, and various
UI improvements across encounters, run list, and journal pages.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Add a guard script that blocks git commit/push on protected branches
(develop, main, master) via a PreToolUse hook. Update CLAUDE.md with
stricter branching rules: one commit per task, immediate commits on
feature branches, no direct commits to protected branches.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
## Summary
- Add `is_admin` column to users table with Alembic migration and a `require_admin` FastAPI dependency that protects all admin-facing write endpoints (games, pokemon, evolutions, bosses, routes CRUD)
- Expose admin status to frontend via user API and update AuthContext to fetch/store `isAdmin` after login
- Make navigation menu auth-aware (different links for logged-out, logged-in, and admin users) and protect frontend routes with `ProtectedRoute` and `AdminRoute` components, preserving deep-linking through redirects
- Fix test reliability: `drop_all` before `create_all` to clear stale PostgreSQL enums from interrupted test runs
- Fix test auth: add `admin_client` fixture and use valid UUID for mock user so tests pass with new admin-protected endpoints
## Test plan
- [x] All 252 backend tests pass
- [ ] Verify non-admin users cannot access admin write endpoints (games, pokemon, evolutions, bosses CRUD)
- [ ] Verify admin users can access admin endpoints normally
- [ ] Verify navigation shows correct links for logged-out, logged-in, and admin states
- [ ] Verify `/admin/*` routes redirect non-admin users with a toast
- [ ] Verify `/runs/new` and `/genlockes/new` redirect unauthenticated users to login, then back after auth
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Reviewed-on: #67
Co-authored-by: Julian Tabel <juliantabel.jt@gmail.com>
Co-committed-by: Julian Tabel <juliantabel.jt@gmail.com>
- Pass SUPABASE_JWT_SECRET to backend in docker-compose.prod.yml
- Add build args (VITE_API_URL, VITE_SUPABASE_URL, VITE_SUPABASE_ANON_KEY)
to Dockerfile.prod so Vite inlines them at build time
- Pass build args from secrets in deploy workflow
- Add build section to frontend service in docker-compose.prod.yml
No GoTrue container needed in prod — Supabase Cloud hosts the auth
service. The backend only needs the JWT secret to verify tokens.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Instead of relying on a pre-existing .env file on the server, the
deploy workflow now writes POSTGRES_PASSWORD and SUPABASE_JWT_SECRET
from Gitea secrets. This keeps all secret management in one place.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
This release adds authentication, role-based access control, and production deployment configuration for Supabase Cloud.
Auth system
ProtectedRouteandAdminRoutecomponents for frontend route protectionRole-based access control
is_admincolumn on users table with Alembic migrationrequire_adminFastAPI dependency protecting admin write endpoints (games, pokemon, evolutions, bosses, routes CRUD)Production deployment
docker-compose.prod.ymlandDockerfile.prod.envfrom Gitea secrets (no manual.envon server)Other changes
Test plan
🤖 Generated with Claude Code