Token resolver now checks the env owner-token (admin) then a staff table (name/token/ role). New require_admin gates /settings/* (API keys/connections) + staff CRUD; everything operational (search/scan/inventory/labels/intake) stays on require_token so staff can do it. admin.html: /admin/me drives ROLE; data-admin nav (Staff + Connections) hidden for staff + go() blocks the views; new Staff tab to add operators, set role, reset/show token once, deactivate. Tokens shown once on create. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| admin.html | ||
| builder.html | ||
| dash.html | ||
| index.html | ||
| nav.js | ||
| pos.html | ||
| records.html | ||
| release.html | ||
| search.html | ||
| shop.html | ||
| wantlist.html | ||