Commit bcc3085
committed
fix: remove admin from sidebar + add PATCH to CORS allowed methods
Two hotfixes:
1. Admin link removed from Sidebar -- was visible to ALL users.
Admin page still accessible via /dashboard/admin URL only.
Non-admins get 403 from backend, clean error in frontend.
2. PATCH added to CORS allow_methods. The admin tier endpoint
uses PATCH but it was missing from the CORS config, causing
preflight failures on the tier update call.
3. Added retry:false to AdminPage React Query so non-admin
users don't hammer the 403 endpoint.1 parent a604655 commit bcc3085
3 files changed
Lines changed: 2 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
84 | 84 | | |
85 | 85 | | |
86 | 86 | | |
87 | | - | |
| 87 | + | |
88 | 88 | | |
89 | 89 | | |
90 | 90 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
6 | 5 | | |
7 | 6 | | |
8 | 7 | | |
| |||
25 | 24 | | |
26 | 25 | | |
27 | 26 | | |
28 | | - | |
29 | 27 | | |
30 | 28 | | |
31 | 29 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
50 | 50 | | |
51 | 51 | | |
52 | 52 | | |
| 53 | + | |
53 | 54 | | |
54 | 55 | | |
55 | 56 | | |
| |||
0 commit comments