Admin (email allowlist) is now gated on a verified email and re-evaluated per
request instead of trusting a frozen cookie flag; session max_age cut to 8h.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Links, form actions, and redirects are prefixed with the gateway path prefix so
the portal can be served at intervalsicu.farhoodlabs.com/portal (gateway strips
/portal; FastAPI root_path generates correct URLs). Connector URL is configurable.
- OIDC login via Authentik; first login creates a disabled user (admin approval).
- Users set/replace their Intervals.icu athlete ID + API key; the key is validated
against Intervals.icu and stored AES-256-GCM encrypted (shared key with the MCP
server). Same users table (schema owned by the MCP server's migrations).
- Admin page (gated on the intervalsicu-mcp-admins group claim): list, approve,
disable, delete users.
- 29 tests @ 93% (OIDC routes integration-only); Dockerfile asserts templates are
packaged; .gitea CI test-gates the image build.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>