Inteligentna Skrzynka

JPM Inwestycje • Back-office AI

Panel operatora • Wymagane logowanie

Logowanie operatora

MVP auth: HTTP-only signed cookie, serwer Next.js waliduje sesję przed proxy do NestJS z OPERATOR_API_KEY. Prod: Supabase Auth + RLS role policies. Frontend nie ma dostępu do Supabase bezpośrednio - tylko NestJS ma service_role.

Demo: operator1 / operator123 • operator2 / operator456 • operator3 / operator789 (zmień w env OPERATOR*_LOGIN/PASSWORD)

Security: server-side secrets, RLS, API key separation, CORS, Zod, human approval

TODO prod: Supabase Auth, Nginx reverse proxy, HTTPS