feat: require owner login and add onboarding

This commit is contained in:
2026-09-28 19:14:14 +09:00
parent 57882cf5f9
commit 85d23a328b
42 changed files with 2400 additions and 23 deletions
+2 -1
View File
@@ -1,7 +1,8 @@
# Shared storage and Mastodon OAuth
Personal Workspace runs as a single personal server behind Tailscale Serve. The
backend binds to loopback and accepts only the configured Tailscale login.
backend binds to loopback. The configured Tailscale identity is an outer access
check; a separate [owner login](login.md) is required in every deployment mode.
Browser requests that change state must have the configured Origin. OAuth
callbacks also pass the owner check; the browser must be able to reach the
tailnet HTTPS address after Mastodon authorization.