Skip to content

WEB: Auth for serve --http #475

@Hmbown

Description

@Hmbown

Summary

Basic-auth via DEEPSEEK_SERVER_PASSWORD, with localhost bypass when env is not set.

Acceptance criteria

  • Browser prompts on first visit.
  • Cookie persists.
  • No auth for 127.0.0.1 by default.

Files

crates/app-server/src/auth.rs (new); apps/web/

Size

S

Source

Source tag: WEB. Add exact upstream/opencode source links during implementation if they are not already known. Do not copy external code blindly; port the behavior into this repo's architecture.

Filed from 2026-05-02 v0.8.8 intake.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestv0.9.0Targeting v0.9.0

    Projects

    Status
    Backlog

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions