Expand description
/ui/login and /ui/logout — the sign-in page and its counterpart.
The only page routes reachable without a session, and the only ones that use
a plain HTML form rather than htmx: there is no CSRF token to send until a
session exists, and signing in should work before a byte of JavaScript has
loaded. What protects the route instead is check_origin, run inside
[crate::webadmin::handlers::session::sign_in] — the same gate, the same
function, as POST /api/session.
Functions§
- get_
login GET /ui/login— the sign-in form.- get_
login_ mfa GET /ui/login/mfa— the second half of signing in.- post_
login POST /ui/login— exchange a username and password for a session cookie.- post_
login_ mfa POST /ui/login/mfa— finish the sign-in with a code.- post_
logout POST /ui/logout[?all=true]— sign out here, or everywhere.