Skip to main content

Module session

Module session 

Source
Expand description

/ui/login and /ui/logout — the sign-in page and its counterpart.

The only page routes reachable without a session, and the only ones that use a plain HTML form rather than htmx: there is no CSRF token to send until a session exists, and signing in should work before a byte of JavaScript has loaded. What protects the route instead is check_origin, run inside [crate::webadmin::handlers::session::sign_in] — the same gate, the same function, as POST /api/session.

Functions§

get_login
GET /ui/login — the sign-in form.
get_login_mfa
GET /ui/login/mfa — the second half of signing in.
post_login
POST /ui/login — exchange a username and password for a session cookie.
post_login_mfa
POST /ui/login/mfa — finish the sign-in with a code.
post_logout
POST /ui/logout[?all=true] — sign out here, or everywhere.