feat: delegate subscription checks to jprq-web - #294
Merged
azimjohn merged 7 commits intoApr 29, 2026
Conversation
Removed redundant error handling for authentication.
Reduce HTTP client timeout from 10 seconds to 2 seconds.
azimjohn
approved these changes
Apr 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Authenticator now consults jprq-web's /api/auth/validate after the GitHub identity step: if the user has an active subscription there, user.Allowed is set to true (with tier info), letting the existing tunnel server check pass. The 42.uz fallback is preserved for legacy identities — calls that already returned Allowed=true skip the extra hop.
The website's auto-allow file write is removed: jprq-web is the new source of truth for desktop users, so /etc/jprq/allowed-users.csv is no longer touched by the OAuth callback. The file-load path in the tunnel server stays as-is for legacy CLI users until that side is also migrated.
Wired via two new env vars on the tunnel server:
JPRQ_WEB_URL — base URL of jprq-web
JPRQ_INTERNAL_TOKEN — shared secret (Bearer) for the internal validate endpoint