1
0
Fork 0
Commit graph

5 commits

Author SHA1 Message Date
c0d00fc113 fix(auth): reject MCP API-key sessions in user auth paths
With the MCP plugin enabled, payload.auth() can return a
payload-mcp-api-keys doc instead of a User. Add an isPayloadUser
type guard and use it in every server action, page, and route that
treats the auth result as a real user, so API-key sessions can no
longer pass user auth checks. hasRoles now explicitly requires a
users-collection doc.
2026-08-25 12:27:35 -04:00
485e26bbda feat(realtime): publish user-scoped update events 2026-08-21 00:25:20 -04:00
1a86a3a8b5 feat(realtime): add channel presence 2026-08-20 19:57:01 -04:00
7db1f648bf style(app): format app routes, pages, and server actions 2026-08-16 23:27:51 -04:00
d3afc6a0c1 feat(realtime): add game-tick SSE notification pipeline 2026-08-02 02:03:56 -04:00