RECORDGOD/app
type-two 9a66f59bfe feat(auth): staff email+password login + password reset (login stays token-based under the hood)
Staff were stuck pasting a raw bearer token with no reset. Now: a proper /login page (email+password)
that exchanges to the staff member's existing token (SPA unchanged downstream). PBKDF2 hashing (stdlib,
no bcrypt dep). New: POST /auth/login, POST /auth/change-password (self), POST /admin/staff/{id}/password
(admin reset). staff gains email(unique)/phone/pay_rate/password_hash. Staff admin UI: add/edit details,
set-password, and timecards now show pay (hours × rate). admin.html redirects to /login when unauthed +
bounces expired tokens; nav gets Change-password + Sign-out. Owner master token still works (break-glass on
the login page). Verified e2e: login, wrong-pw 401, token auth, admin reset invalidates old pw.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-26 16:24:34 +10:00
..
__init__.py feat: RecordGod founding — service scaffold + MariaDB→Postgres migration 2026-06-19 17:18:50 +10:00
admin_routes.py feat(auth): staff email+password login + password reset (login stays token-based under the hood) 2026-06-26 16:24:34 +10:00
auth_routes.py feat(auth): staff email+password login + password reset (login stays token-based under the hood) 2026-06-26 16:24:34 +10:00
auth.py feat(auth): staff email+password login + password reset (login stays token-based under the hood) 2026-06-26 16:24:34 +10:00
collections_routes.py feat(collections): interactive editor — click-map crate select, genre/style/price/year rules, live match stats, priority 2026-06-22 21:33:15 +10:00
db.py feat: RecordGod founding — service scaffold + MariaDB→Postgres migration 2026-06-19 17:18:50 +10:00
disc_images.py feat(intake): ScanGod bridge — POST /admin/intake/scan (photo→staged product) + reply 2026-06-24 17:16:18 +10:00
intake_routes.py perf(search): pg_trgm fuzzy staff search — typo-tolerant, multi-word, ~100ms (was ILIKE seq scan) 2026-06-25 16:10:36 +10:00
layout_routes.py feat(shop): P4 wantlist — public 'request a record' page + admin queue 2026-06-23 01:29:00 +10:00
mailer.py feat(pos): rebuild Sales — 3 tabs, smooth checkout + tender/change, print+email receipts 2026-06-23 16:29:42 +10:00
main.py feat(auth): staff email+password login + password reset (login stays token-based under the hood) 2026-06-26 16:24:34 +10:00
mirror.py feat: self-contained enrichment — disc_cache (own catalog copy), no external DB dependency 2026-06-21 13:16:56 +10:00
navigator_routes.py feat(nav): Quick Insert + click-to-pick insert slot (insert-with-shift) 2026-06-23 19:45:42 +10:00
receipts.py feat(pos): receipt logo + Monster Robot template (store name/address/footer) 2026-06-23 17:33:08 +10:00
sales_routes.py feat(shipping): use current AusPost own-packaging rates (RecordGod not live pre-1-Jul, no dating needed) 2026-06-24 01:05:12 +10:00
settings_routes.py feat(connect): OpenRouter key + test in vault; AI agent integration plan 2026-06-24 16:12:19 +10:00
shop_routes.py feat(bridge): RecordGod WP bridge plugin (WowPlatter successor) + thumb on browse/release 2026-06-24 01:43:30 +10:00
square.py feat(pos): Square Terminal payments — push checkout to a paired terminal 2026-06-23 17:57:26 +10:00
vault.py feat: standalone RecordGod web UI — landing, control-room dash, encrypted secrets vault 2026-06-21 12:40:07 +10:00
virtual.py feat(virtual): finish the 3D store port — per-room scoping, decals, portals 2026-06-21 21:00:02 +10:00
wowplatter_v1.py feat(intake): wowplatter/v1 intake carries est_market_value (DealGod target from PRICEGOD) 2026-06-25 02:00:40 +10:00