使用 Supabase Auth 登录。初始演示密码见种子脚本。
Authentication is Supabase Auth (email + password · OAuth 可后续开启) · staff bit is enforced via the is_staff JWT claim.
SourcingHub2026!. Each role demonstrates a different RBAC bucket — four-eyes approvals, audit-log capture, and permission surfaces adapt automatically.