All the ledger data is confidential (real client names, amounts, associate balances) -- revoke 'access content' from the anonymous role so nodes, taxonomy terms, and JSON:API all deny anonymous reads (verified: JSON:API returns an empty data[] + "omitted" notice instead of the records, /lignes and /dashboard 403). Set the site's 403 page to /user/login: anonymous visitors hitting "/" (the front page is /lignes) land on the login form instead of an access-denied page; authenticated users still land on /lignes as before since they still hold 'access content' via the authenticated role. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
16 lines
343 B
YAML
16 lines
343 B
YAML
_core:
|
|
default_config_hash: ijfbzDTN4CbE7Sr-6ubWzy_t1vH4OtU1doNCLssVz-4
|
|
langcode: en
|
|
uuid: 771fd453-fb55-4eb0-bbc9-52fa9697d2b8
|
|
name: 'Figures Libres - Compta'
|
|
mail: admin@example.com
|
|
slogan: ''
|
|
page:
|
|
403: /user/login
|
|
404: ''
|
|
front: /lignes
|
|
admin_compact_mode: false
|
|
weight_select_max: 100
|
|
default_langcode: en
|
|
mail_notification: null
|