From cc77b35e328df9ec06e814a09022fc71595cbe21 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 15 Sep 2026 18:05:17 -0400 Subject: [PATCH] docs(auth): document Cognito workspace variables --- README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/README.md b/README.md index c1f3746..facbca3 100644 --- a/README.md +++ b/README.md @@ -113,6 +113,8 @@ sit in ALARM between runs). Alarm names follow `meal-order-manager-- Google Identity Services and portal Cognito ID tokens coexist until portal cutover. Google tokens use the tokeninfo endpoint. Portal tokens are verified locally against the configured Cognito issuer, audience, signature, expiry, token use, and email domain. Both paths accept only `seahavenind.com` and `seahaven.com` identities and fail closed when their SSM configuration is unavailable. The local Flask workflow can still use manual name and email entry when Google auth is not configured. +Set the `portal_cognito_issuer` and `portal_cognito_audience` HCP Terraform workspace variables from the matching internal-portal stage outputs. Switch both values together when moving from dev validation to the production portal pool. + ## Admin Panel Admins (configured in DynamoDB `CONFIG/SETTINGS` → `admin_emails` list) get an "Admin" button after Google sign-in. The panel provides: