Sign in

Email + password auth is now wired for the web app.

Admin access is driven by the authenticated user's metadata/claims. Next backend step: enforce the same role checks in database policies and protected API routes.

Educational only. Not financial advice.