Skip to content

Add no-auth Spring profile for frictionless local development - #113

Merged
nilskntl merged 2 commits into
masterfrom
83-disable-auth-in-local-spring-profile-with-dev-user-fallback
Mar 21, 2026
Merged

nilskntl merged 2 commits into
masterfrom
83-disable-auth-in-local-spring-profile-with-dev-user-fallback

Conversation

@claude

@claude claude Bot commented Mar 21, 2026

Copy link
Copy Markdown

Summary

  • Adds a no-auth Spring profile (SPRING_PROFILES_ACTIVE=no-auth) that starts without Cognito/AWS credentials — all secrets get placeholder values, JWT validation is skipped, and every request is permitted
  • Injects a hardcoded dev user (dev-user / dev@local) as the authenticated principal; the user is auto-persisted in Neo4j on first request and defaults to the FREE subscription tier
  • GET /api/public/config now returns {"authEnabled": false} when the no-auth profile is active
  • Frontend detects authEnabled: false at bootstrap, skips Amplify.configure(), injects a synthetic dev user, and redirects /auth/** straight to /app/classes
  • Auth remains fully enforced in local, test, and prod profiles — no regression

Issue

Closes #83

Generated with Claude Code

Implements #83

- Add `no-auth` Spring profile: permits all HTTP requests without JWT,
  provides placeholder values for all secrets so Cognito/AWS credentials
  are not required at startup (`SPRING_PROFILES_ACTIVE=no-auth`)
- `NoAuthSecurityConfig`: profile-exclusive security chain that allows
  every request; mirrors CORS config from production `SecurityConfig`
- `SecurityConfig`: restricted to `!no-auth` via `@Profile`
- `CognitoConfig`: Cognito properties now have empty-string defaults so
  startup succeeds when `no-auth` is active and Cognito IDs are absent
- `CurrentUser`: when `auth.disabled=true`, injects a stable hardcoded
  dev-user sub (`00000000-0000-0000-0000-000000000dev`), skips JWT
  extraction and returns a hardcoded `CognitoUser` ("Dev User",
  dev@local); dev user is auto-persisted in Neo4j on first request
- `AuthConfigDto`: adds `authEnabled` field (default `true`) so the
  frontend knows whether to show the Cognito login flow
- `PublicController`: returns `{"authEnabled": false}` on `/api/public/config`
  when `auth.disabled=true`
- Frontend `AuthConfig` type: adds optional `authEnabled` field
- `main.tsx`: skips `Amplify.configure()` when `authEnabled === false`
- `useAuth.tsx`: sets synthetic dev user immediately when auth is
  disabled; exposes `authEnabled` through the auth context
- `AuthPage`: redirects to `/app/classes` when `authEnabled === false`
- `api-client.ts`: skips `fetchAuthSession()` and 401→/auth redirect
  when auth is disabled

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@claude claude Bot linked an issue Mar 21, 2026 that may be closed by this pull request
5 tasks
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@nilskntl
nilskntl merged commit 43cd8b8 into master Mar 21, 2026
2 checks passed
@nilskntl
nilskntl deleted the 83-disable-auth-in-local-spring-profile-with-dev-user-fallback branch March 21, 2026 00:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Disable auth in local Spring profile with dev user fallback

1 participant