God mode global state + session expiration at zero verification
1. God Mode State (useUserInfo hook): - Move isGodMode to GLOBAL state in hook (not local to NavTop) - Export isGodMode, setIsGodMode for all components ...
Move god mode state to global useUserInfo hook
BREAKING FIX: Properly separates isGod and isGodMode Architecture (as intended): - isGod: Permission from session (GD field) - Can user access god mode? - isGo...
Add explicit handlers and keys to switches
- Add handleAcceptingLeadsToggle and handleGodModeToggle handlers - Add unique keys and names to both switches - Add aria-labels for accessibility - Helps React...
God mode toggle state and add fire icon
Bug fix: - God Mode switch was using isGodModeActive() from hook for 'checked' prop - But onChange was calling setGodModeActive (local state) - This created a d...
Add multi-layer god mode validation
Security enhancements to prevent localStorage manipulation: 1. useUserInfo hook: - Add isGodModeActive() method with dual validation - Check 1: User has ...
Implement god mode toggle in NavTop
Backend changes (app/api/user-info/route.ts): - Read GD field from Redis session data - Map to isGod in API response Frontend changes (app/hooks/useUserInfo.ts...
Implement god mode permission in sessions
Changes to SecurityController: - Query is_god field from users table during login - Pass isGod to kSessionService.createSession Changes to KSessionService: - A...
IsGod フィールドを User.java に追加して、God モードの権限を追加します
- データベースのデフォルトで is god カラムを追加 - フィールドは、ユーザーがUIで神モードのトグルにアクセスできるかどうかを示します - セキュリティサービスセッション作成で GD パラメータをカプセル化 - 神モードの特徴の実装の一部
[ログイン] の Cookie を設定します。* ドメインは自動ログイン時に設定します
BREAKING:ユーザーが有効なセッションを持っているときに自動ログインを有効にします 以前:*** クッキーは、OTK検証後に内部.*ドメインでのみ作成されます。 後:*** BOTH login.* および内部で作成されるクッキー。* ドメイン 変更点: - app/api/login/route.ts: O...
Ensure all session expirations go through /logout endpoint
BREAKING: Fixes improper session expiration flow Before: Various components redirected directly to login site when sessions expired After: All redirects go thr...
Add titleShort to organization API response
- Added titleShort field to /org/domain/{domain} endpoint response - Enables frontend to display organization's short name in UI - Used in session expiration wa...
Dynamically show org short name in session warning
- Added titleShort property to Organization class - Updated SessionExpirationWarning to use organization's short name - Changed text from 'Kamo applications' to...
Remove remaining KTokenSessionService reference in refresh-token endpoint
- Updated /refresh-token endpoint to use **************** - Removed unused KToken import - Changed endpoint to extend session TTL instead of refreshing KToken o...
Consolidate session management into KSessionService
- Deleted duplicate KTokenSessionService - Enhanced KSessionService with: * getSessionTTL() - get Redis key TTL * getSessionInfo() - get session data + TTL ...
Add missing properties to SessionInfo interface
- Added userId, orgId, memberId, tokenExpiration to SessionInfo - These fields are returned by backend getSessionInfo() method - Fixes TypeScript build error in...
Remove problematic timezone endpoint and duplicate getSessionIdFromCookie
- Removed **************** endpoint (no longer needed, timezone is in *** cookie) - Removed duplicate getSessionIdFromCookie method that was causing compilation...
Double-check Redis before showing session warning
- Always verify Redis TTL right before showing expiration warning - Prevents false warnings if another Kamo app extended the session - Ensures warning popup onl...
Implement sliding session expiration - CRITICAL SESSION FIX
- Refresh Redis TTL on every session access (sliding expiration) - Sessions now stay alive as long as user is active in ANY Kamo app - Change Redis key prefix f...