Skip to main content

Module session

Module session 

Source
Expand description

POST/GET/DELETE /api/session — sign in, whoami, sign out.

Every failed sign-in answers one invalid_credentials, whatever the cause; the reason (wrong_password, unknown_user, account_disabled) is only in the admin_login_failed log line. An operator with a second factor gets a pending_mfa session first, which can do nothing but finish the login.

Structs§

LoginRequest
The credentials of POST /api/session, and of the sign-in page’s form.
LogoutQuery
The query of a sign-out, DELETE /api/session or its page twin.
MfaRequest
The submission that finishes a login: a TOTP code, or a recovery code. One field, because the operator types whichever they have into the same box.

Functions§

delete_session
DELETE /api/session[?all=true] — sign out.
get_session
GET /api/session — who am I, and what is my CSRF token.
get_session_mfa
GET /api/session/mfa — what this half-authenticated cookie still owes.
post_session
POST /api/session — exchange a username and password for a session cookie.
post_session_mfa
POST /api/session/mfa — finish a login with a code.