Problem
Running the local dev stack currently requires valid Cognito credentials (User Pool ID, Client ID) even though local development doesn't need real authentication. This creates unnecessary friction when spinning up the stack locally.
Desired Behavior
Backend new Profile (no-auth Spring profile)
- Skip JWT validation entirely when
SPRING_PROFILES_ACTIVE=no-auth
- Inject a hardcoded dev user as the current authenticated principal for all requests — no token required
- The dev user should be persisted in the database so all other queries will work
- No startup errors / warnings for missing Cognito User Pool ID or Client ID when running locally
Frontend
The frontend currently reads auth config (config endpoint) from the backend (e.g. whether Cognito is enabled, redirect targets). It should respect a flag returned by the backend config endpoint:
- When the backend signals "auth disabled" (local mode), skip the
/auth login flow entirely
- Redirect directly from
/auth/** routes to the app pages (e.g. /app/classes)
- No login screen, no Cognito redirect — the user lands straight in the app
Acceptance Criteria
Notes
- The backend config endpoint (used by the frontend to bootstrap auth settings) must expose an
authEnabled: false flag in local mode
SecurityConfig.java is the main touchpoint on the backend — be careful not to weaken security in other profiles
Problem
Running the local dev stack currently requires valid Cognito credentials (User Pool ID, Client ID) even though local development doesn't need real authentication. This creates unnecessary friction when spinning up the stack locally.
Desired Behavior
Backend new Profile (
no-authSpring profile)SPRING_PROFILES_ACTIVE=no-authFrontend
The frontend currently reads auth config (config endpoint) from the backend (e.g. whether Cognito is enabled, redirect targets). It should respect a flag returned by the backend config endpoint:
/authlogin flow entirely/auth/**routes to the app pages (e.g./app/classes)Acceptance Criteria
SPRING_PROFILES_ACTIVE=no-authstarts without errors whencognito.userPoolId/cognito.clientIdare not set/auth→/app/classes(or equivalent home) when backend reports auth as disabledtestorprodprofiles — auth remains fully enforced there. Using only thelocalprofile withoutno-authshould have the same behavior as beforeNotes
authEnabled: falseflag in local modeSecurityConfig.javais the main touchpoint on the backend — be careful not to weaken security in other profiles