meal-order-manager/.github/workflows
Adam Moussa 311eab35c0
fix(auth): require Google authentication in cloud mode (#90)
* fix(auth): require Google authentication in cloud mode

Remove the public shared-key mechanism and fail closed on Google auth while adding submit-route throttling.

* fix(auth): address review follow-ups

Fail closed on whitespace-only Google configuration and centralize shared authentication behavior.

* test(auth): use non-secret Google client fixture

Make the public test identifier explicit so secret scanning does not misclassify it as an API key.

* test(auth): avoid OAuth-shaped fixture

Use a format-neutral audience value so secret scanning can distinguish the fixture from a real client identifier.

* chore(security): suppress public OAuth fixture

Document the scanner false positive without suppressing any runtime credential flow.
2026-08-03 13:51:12 -04:00
..
ci.yml chore(deps): bump the minor-and-patch group with 4 updates (#96) 2026-08-03 13:39:41 -04:00
dependency-review.yml chore(deps): bump the minor-and-patch group with 4 updates (#96) 2026-08-03 13:39:41 -04:00
deploy.yml chore(deps): bump the minor-and-patch group with 4 updates (#96) 2026-08-03 13:39:41 -04:00
labeler.yml chore(deps): bump the minor-and-patch group with 4 updates (#96) 2026-08-03 13:39:41 -04:00
weekly-menu.yml fix(auth): require Google authentication in cloud mode (#90) 2026-08-03 13:51:12 -04:00