fix: Revert to secure default authentication configuration
deploy / deploy (push) Successful in 2m23s
deploy / notify (push) Successful in 1s

- Restore appsettings.json Authentication.Mode to FailClosed (production default)
- Restore Program.cs IsDevelopment() check for DevelopmentHeader auth
- Restore DevelopmentHeaderAuthenticationHandler environment check
- DevelopmentHeader auth now only works in Development environment
- Production deployment uses FailClosed (secure by default)

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
This commit is contained in:
2026-08-12 00:36:12 +09:00
parent 58a8d45638
commit b1d2c03810
3 changed files with 9 additions and 2 deletions
+2 -1
View File
@@ -234,7 +234,8 @@ var authenticationBuilder = builder.Services
options.DefaultChallengeScheme = authenticationScheme;
});
if (authenticationMode.Equals("DevelopmentHeader", StringComparison.OrdinalIgnoreCase))
if (builder.Environment.IsDevelopment()
&& authenticationMode.Equals("DevelopmentHeader", StringComparison.OrdinalIgnoreCase))
{
authenticationBuilder.AddScheme<AuthenticationSchemeOptions, DevelopmentHeaderAuthenticationHandler>(
authenticationScheme,