Skip to content

Document Trivet owner account setup - #2

Closed
philipithomas wants to merge 1 commit into
mainfrom
codex/admin-user-setup
Closed

philipithomas wants to merge 1 commit into
mainfrom
codex/admin-user-setup

Conversation

@philipithomas

Copy link
Copy Markdown
Contributor

Summary

  • clarify that Trivet has owner accounts rather than an application admin role
  • distinguish Google-authenticated owner access from Ghost Admin API credentials
  • document how a publisher account is created

Validation

  • pnpm check
  • pnpm lint
  • pnpm format:check
  • pnpm build

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9f76efb38f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread README.md
Trivet does not have a separate application admin role or an admin-user
allowlist. A publisher becomes an owner by choosing **Sign up** on the Trivet
homepage and completing Google authentication. The OAuth callback creates (or
updates) an `Account` using the verified Google email address, and all signed-in

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Don't claim owner emails are verified

This says the OAuth callback uses a verified Google email address, but the callback paths call verifyIdToken and then pass userInfo.email into handleOwnerSignIn; verifyIdToken only checks that an email field exists and never enforces email_verified. If Google returns an unverified email claim, the README overstates the owner-account guarantee and can mislead operators auditing how publisher accounts are created; either remove “verified” here or enforce the claim in the callback.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant