- msal_auth.py: replace verify_signature=False with real JWKS verification using PyJWKClient; validates RS256 signature, aud=clientId, issuer v2.0 - App.tsx: split DEV bypass from empty-accounts case — in production, accounts.length === 0 now correctly triggers loginRedirect instead of calling fetchMe without a token Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| middleware.py | ||
| msal_auth.py | ||
| user_store.py | ||