auth
-
Session Auth
Google signs the user in, then the session stores the selected demo role and re-hydrates it on every request.
-
Session Payloads
Semitexa forbids string-key session chaos: session state lives in typed Session Payloads or it does not exist.
-
Google Authorization
Authorization is required for demo SSE blocks that keep a long-lived backend connection open.
-
Machine Auth
Service-to-service authentication via Bearer tokens — scoped, revocable, and audited.
-
Protected Route
Add one access attribute and one optional permission attribute and the framework enforces access — 401 for unauthenticated requests, 403 for unauthorized ones.
-
Requires Permission
Declare one permission slug on the payload and let the framework enforce it before your handler runs.
-
RBAC
Hybrid RBAC with coarse-grained capabilities, exact permission slugs, and module-owned permission catalogs.