Skip to content

Stabilize staging Access redirects and document Cloudflare tokens - #24

Merged
dills122 merged 4 commits into
mainfrom
codex/staging-access-token-docs
Jun 11, 2026
Merged

dills122 merged 4 commits into
mainfrom
codex/staging-access-token-docs

Conversation

@dills122

Copy link
Copy Markdown
Owner

Summary

  • Adjusts staging Cloudflare Access configuration to avoid redirect/session friction during GitHub OAuth.
  • Documents Cloudflare API token permission profiles for local infra, deploy automation, and temporary recovery.
  • Keeps staging Access scoped to the canonical custom hostname by default.

What Changed

  • Changed staging Access cookie configuration from hardcoded SameSite=Strict to configurable SameSite=Lax.
  • Removed staging.forage-web.pages.dev from the default Access app hostname guidance.
  • Documented that Pages preview URLs should be protected separately through Cloudflare Pages settings.
  • Added docs/24-cloudflare-token-permissions.md with full infra, deploy, and security recovery token profiles.
  • Linked the new token-permissions doc from hosting setup, IaC, deployment automation, docs index, and OpenTofu README.

Validation

  • tofu plan -refresh=false
  • npm run check
  • npm run check:docs
  • npm run check:workspace
  • npm run infra:fmt:check

Scope Notes

  • Live Cloudflare apply was not completed because the current TEMP_CLOUDFLARE_API_TOKEN verifies as invalid.
  • The targeted OpenTofu plan showed one intended Access app update: remove staging.forage-web.pages.dev and change same_site_cookie_attribute from strict to lax.
  • Once a valid token is available, apply with the documented targeted recovery command or a full infra token.

@dills122
dills122 merged commit e013128 into main Jun 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant