Files
DeskcommCRM/lib/auth
Rafael MelgaçoandClaude Opus 4.7 975b0242b5 feat(EPIC-11): admin layout + guard + banner [wave 1]
Foundation for the Super-Admin Platform sub-product:
- requirePlatformAdmin server helper: getUser → check platform_admins
  row + AAL2 (MFA recente). Redirects /admin/forbidden or /login/mfa.
- middleware.ts branches on host=admin.* OR path=/admin/* (early
  redirect to /login if no auth cookie). DB check stays server-side.
- AdminShell + PlatformModeBanner (sticky amber banner, role=region) +
  AdminSidebar (14 entries with distinct Phosphor icons).
- /admin redirects to /admin/dashboard (stub for S-11.02).
- /admin/forbidden 403 page outside the protected layout group.

In dev: works via http://localhost:3000/admin/* (no hosts file needed).
In prod: admin.deskcomm.com sub-domain via Vercel rewrites (deferred).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 13:09:49 -03:00
..