Skip to content

Disable auth in local Spring profile with dev user fallback #83

Description

@nilskntl

Problem

Running the local dev stack currently requires valid Cognito credentials (User Pool ID, Client ID) even though local development doesn't need real authentication. This creates unnecessary friction when spinning up the stack locally.

Desired Behavior

Backend new Profile (no-auth Spring profile)

  • Skip JWT validation entirely when SPRING_PROFILES_ACTIVE=no-auth
  • Inject a hardcoded dev user as the current authenticated principal for all requests — no token required
  • The dev user should be persisted in the database so all other queries will work
  • No startup errors / warnings for missing Cognito User Pool ID or Client ID when running locally

Frontend

The frontend currently reads auth config (config endpoint) from the backend (e.g. whether Cognito is enabled, redirect targets). It should respect a flag returned by the backend config endpoint:

  • When the backend signals "auth disabled" (local mode), skip the /auth login flow entirely
  • Redirect directly from /auth/** routes to the app pages (e.g. /app/classes)
  • No login screen, no Cognito redirect — the user lands straight in the app

Acceptance Criteria

  • SPRING_PROFILES_ACTIVE=no-auth starts without errors when cognito.userPoolId / cognito.clientId are not set
  • All authenticated API endpoints return data for the hardcoded dev user without requiring a Bearer token
  • Frontend redirects /auth → /app/classes (or equivalent home) when backend reports auth as disabled
  • No regression in test or prod profiles — auth remains fully enforced there. Using only the local profile without no-auth should have the same behavior as before
  • Dev user has sensible defaults (e.g. name "Dev User", a stable UUID, free-tier subscription)

Notes

  • The backend config endpoint (used by the frontend to bootstrap auth settings) must expose an authEnabled: false flag in local mode
  • SecurityConfig.java is the main touchpoint on the backend — be careful not to weaken security in other profiles

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    featureNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions