I currently have a React single page app, where I have setup Firebase Auth to help me access my Firestore DB from the client side. I hired a developer to build me an admin panel, which he ended up building in Django (bad idea in hindsight but it's done now). I containerized it and put it on a GCP Cloud Run function. Now, the part I'm stuck at is that I only want to give site admins access to the admin panel.
Using Google IAM, I've restricted access to the Admin panel URL to some users' email IDs, and I now want to somehow connect the auth I have already set up in the main site to get passed to the admin panel.
I'm planning on deploying the admin panel to a subdomain on my site. I am wondering if I can somehow save the JWT from Firebase Auth so that it automatically gets passed when a user tries to access the subdomain. Is this even possible? Can someone suggest an alternate design if this approach is a deadend?