13e8e73da7
The browser UI signs in with a Discord authorization code grant (identify + guilds.members.read) instead of a shared password. Guild membership is the gate; the owner's Discord ID is the only identity allowed in while registration is closed. Sessions become rows in a sessions table with opaque random ids — the cookie carries only the id, looked up and expiry-checked per request — so deleting a row revokes a session. HMAC cookie signing, its derived key, and WEB_PASSWORD are gone, and no replacement signing secret is introduced (ADR-0002). Discord's API base is configurable (DISCORD_API_BASE); the full flow is tested through the real router against a local stub, including the form-encoded token exchange Discord rejects if sent as JSON.
33 lines
1.2 KiB
HTML
33 lines
1.2 KiB
HTML
{{define "login"}}
|
|
<!doctype html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="utf-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover">
|
|
<meta name="color-scheme" content="dark light">
|
|
<title>BookmarkManager</title>
|
|
<link rel="icon" href="/static/logo.svg" type="image/svg+xml">
|
|
<link rel="stylesheet" href="/static/style.css">
|
|
<link rel="preload" href="/static/fonts/instrument-serif-400-latin.woff2" as="font" type="font/woff2" crossorigin>
|
|
</head>
|
|
<body>
|
|
<main class="login-card">
|
|
<div>
|
|
<span class="eyebrow">Private library</span>
|
|
<h1 class="brand">{{template "mark" .}}<span>Bookmark<em>Manager</em></span></h1>
|
|
</div>
|
|
<figure class="login-art" aria-hidden="true">
|
|
<img src="/static/login-art.png" alt="">
|
|
</figure>
|
|
<form method="get" action="/auth/discord">
|
|
{{/* The page reloads on a failed sign-in, so the message is present from
|
|
the start; role=alert is what gets it announced anyway. */}}
|
|
<p class="error" role="alert">{{.Error}}</p>
|
|
<button type="submit">Continue with Discord</button>
|
|
</form>
|
|
<p class="login-note">Guild membership is required to sign in.</p>
|
|
</main>
|
|
</body>
|
|
</html>
|
|
{{end}}
|