Expand description
POST/GET/DELETE /api/session — sign in, whoami, sign out.
Every failed sign-in answers one invalid_credentials, whatever the cause;
the reason (wrong_password, unknown_user, account_disabled) is only in
the admin_login_failed log line. An operator with a second factor gets a
pending_mfa session first, which can do nothing but finish the login.
Structs§
- Login
Request - The credentials of
POST /api/session, and of the sign-in page’s form. - Logout
Query - The query of a sign-out,
DELETE /api/sessionor its page twin. - MfaRequest
- The submission that finishes a login: a TOTP code, or a recovery code. One field, because the operator types whichever they have into the same box.
Functions§
- delete_
session DELETE /api/session[?all=true]— sign out.- get_
session GET /api/session— who am I, and what is my CSRF token.- get_
session_ mfa GET /api/session/mfa— what this half-authenticated cookie still owes.- post_
session POST /api/session— exchange a username and password for a session cookie.- post_
session_ mfa POST /api/session/mfa— finish a login with a code.