Local HTTPS and Safari sign-in
Neon Auth uses Secure session cookies. Safari cannot keep these on a plain HTTP preview. Use npm run dev:https, then open https://localhost:5174. The launcher redirects old http://127.0.0.1:5173 bookmarks to HTTPS. Stop any existing development server before starting this command.
Certificates are machine-local and excluded from source and archives. On a fresh machine, generate a localhost certificate and trust it with the machine owner's approval:
mkdir -p certificates
openssl req -x509 -newkey rsa:2048 -sha256 -days 90 -nodes -keyout certificates/localhost-key.pem -out certificates/localhost.pem -subj '/CN=localhost' -addext 'subjectAltName=DNS:localhost,IP:127.0.0.1,IP:::1' -addext 'basicConstraints=critical,CA:FALSE'
chmod 600 certificates/localhost-key.pem
# macOS: explicitly trust only this certificate for localhost SSL.
security add-trusted-cert -r trustRoot -p ssl -s localhost -k "$HOME/Library/Keychains/login.keychain-db" certificates/localhost.pem
npm run dev:httpsThe launcher passes the certificate to Node for its own HTTPS calls, keeps the server bound to loopback, and sets the internal agent origin to the HTTPS app. Production should use the hosting provider's normal HTTPS certificate. Never commit the private key.
Account setup now checks the actual session before redirecting. Creating an account without a retained session keeps the user on the sign-in page with an explanation. Account settings displays the authenticated user's email and verification status; name changes are saved through Neon Auth. The public landing page does not embed the private workspace. Signed-out requests to /app redirect to /auth/sign-in, and sign-out returns there immediately.
Source captured: 2026-10-11