Voeg auto-inlog toe per tenant

Genereert een HMAC-gesigneerd token (60s geldig) en redirect naar
<slug>.rikxplatform.nl/auto-login. Token bevat userId, accountId en
expiry; gedeeld AUTO_LOGIN_SECRET verifieert de handtekening.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Maarten Elsenaar
2026-09-15 13:43:54 +02:00
parent c293669dd2
commit ff395ac959
2 changed files with 43 additions and 1 deletions
+14 -1
View File
@@ -3,6 +3,7 @@ import { getSession } from "../../lib/auth";
import { listAccounts } from "../../lib/platform-db";
import { createTenant, deleteTenant } from "./actions";
import { logout } from "./logout";
import { autoLogin } from "./auto-login";
export default async function TenantsPage({
searchParams,
@@ -56,7 +57,7 @@ export default async function TenantsPage({
<th className="text-left px-4 py-3 font-medium">URL</th>
<th className="text-left px-4 py-3 font-medium">Gebruikers</th>
<th className="text-left px-4 py-3 font-medium">Aangemaakt</th>
<th className="px-4 py-3"></th>
<th className="px-4 py-3" colSpan={2}></th>
</tr>
</thead>
<tbody className="divide-y divide-zinc-100 dark:divide-zinc-800">
@@ -78,6 +79,18 @@ export default async function TenantsPage({
<td className="px-4 py-3 text-zinc-500 dark:text-zinc-500 text-xs">
{new Date(a.created_at).toLocaleDateString("nl-NL")}
</td>
<td className="px-4 py-3 text-right">
<form action={autoLogin}>
<input type="hidden" name="account_id" value={a.id} />
<input type="hidden" name="slug" value={a.slug} />
<button
type="submit"
className="text-xs text-blue-600 hover:text-blue-800 dark:text-blue-400 dark:hover:text-blue-300 transition-colors"
>
Inloggen
</button>
</form>
</td>
<td className="px-4 py-3 text-right">
<form action={deleteTenant}>
<input type="hidden" name="account_id" value={a.id} />