Auth · community
GitHub sign-in (MVP)
Unofficial community login on rea.run. Used for light stats and faster deep links to the rea-run-lab Actions / Codespaces flows and case submission. Not affiliated with REA upstream maintainers.
Status:
What we store
- After OAuth, the server drops the GitHub access token.
- An HttpOnly Secure session cookie keeps only profile fields: id, login, avatar (HMAC-signed).
- Nothing sensitive is written to
localStorage.
Operator: enable OAuth
- Create a GitHub OAuth App (Developer settings → OAuth Apps).
- Homepage URL:
https://rea.run - Authorization callback URL:
https://rea.run/api/auth/github/callback(also addhttps://www.rea.run/api/auth/github/callbackif used). - Set Cloudflare Pages secrets on project
rea-run:
Example:GITHUB_OAUTH_CLIENT_ID GITHUB_OAUTH_CLIENT_SECRET SESSION_SECRETnpx wrangler pages secret put GITHUB_OAUTH_CLIENT_ID --project-name=rea-run - Redeploy Pages so Functions see the secrets.