Expand description
Login and sessions: magic links, GitHub OAuth, the session cookie, the Origin check, and
the CurrentUser extractor every signed-in route takes.
Modules§
- Email addresses: a light validity check, and the canonical form used to find an account.
- github
- “Sign in with GitHub”: the OAuth web flow. A random
statevalue in a short-lived cookie ties the callback to the browser that started it. The account email is the user’s primary verified GitHub email, so a GitHub login and a magic link for that address are one account. - magic
- Magic links: a 32-byte random token, stored hashed, valid for 15 minutes, usable once.
- mailer
- Sending login emails. The mailers live in
codoseo-notify(log, capture for tests, SMTP); this module re-exports them so the web crate and its tests keep one import path. - origin
- Spec section 8: every POST checks
Origin. A state-changing request whoseOrigin(or, if a browser left that out,Referer) isn’t this app’s own origin is refused with a 403, which stops cross-site form posts even though sessions useSameSite=Laxcookies. - session
- Random tokens, their hashes, and the session cookie.
Structs§
- Current
User - The signed-in account. Taking this as a handler argument makes the route require a login.
Enums§
- Auth
Rejection - Sends a signed-out visitor to
/login, coming back to where they were afterwards.
Functions§
- load_
site - One of the user’s sites, or a 404 (another account’s site looks exactly like a missing one).
- router
- safe_
next - Only same-site relative paths are allowed as a post-login destination, so
?next=can’t be used to bounce a user to another site. Browsers drop tabs and newlines from a redirect address (/\t/evil.combecomes//evil.com), so any whitespace or control character rejects the value outright; it also keeps theLocationheader valid. - signup_
policy - The policy for creating accounts in this mode.
- urlencode