feat(backend): password login, session gate, and list page

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-25 23:03:00 +07:00
parent e3d86e826c
commit f70707f154
9 changed files with 525 additions and 0 deletions
+11
View File
@@ -61,6 +61,17 @@ func newRouter(store *Store, cfg Config) http.Handler {
mux.Handle("/bookmarks", auth)
mux.Handle("/bookmarks/", auth)
// The browser UI is registered only when a password is configured, so a
// deployment that forgets WEB_PASSWORD exposes nothing rather than
// exposing an unprotected list.
if cfg.WebPassword != "" {
web, err := newWebHandler(store, cfg)
if err != nil {
log.Fatalf("web handler: %v", err)
}
web.register(mux)
}
return withCORS(cfg.AllowedOrigins, mux)
}