Authentication
Dashboard Auth
How partner dashboard authentication routes and dashboard-only API calls should be understood.
First created Last updated
End-to-end developer runbook
- Step 1 - Confirm the API area: Identify the product area, route module, endpoint path, and consumer before writing or calling code.
- Step 2 - Read the endpoint contract: Check method, auth, parameters, response, errors, side effects, and related docs.
- Step 3 - Prepare authentication and input: Use the right session, bearer token, webhook secret, or internal header. Validate body and query data before sending it.
- Step 4 - Make the request: Call the endpoint from the correct origin and environment. Keep credentials and secrets out of logs.
- Step 5 - Verify response, side effects, and records: Confirm status code, response shape, database records, external side effects, and audit evidence.
- Step 6 - Add tests, docs, and handoff notes: Update route inventory, consumer notes, and certification checks before depending on the change.
Dashboard auth model
- Action 1 - Start at
auth.ts: Inspect login, logout, refresh, profile, and development helper routes. - Action 2 - Follow
require-auth.ts: Confirm how the session is read, verified, and attached to Hono variables. - Action 3 - Check partner context: Dashboard routes often need a partner, staff profile, or platform role after basic auth.
- Action 4 - Confirm cookie behavior: Browser requests must use the correct origin and credential mode.
Stop conditions
- Checkpoint 1 - Unknown session source: Stop if you cannot tell whether a route accepts cookies, bearer tokens, or both.
- Checkpoint 2 - Unknown actor: Stop if the route mutates records without a clear actor ID.
- Checkpoint 3 - Unknown partner scope: Stop if a route can cross partner boundaries without an explicit platform-admin reason.