Add explicit login functionality
This commit is contained in:
+12
-16
@@ -16,7 +16,7 @@ import (
|
||||
// resolves it and renders who the caller is.
|
||||
const tokenCookie = "send_token"
|
||||
|
||||
// rememberFor is how long a remembered token survives. Tokens are revoked by
|
||||
// rememberFor is how long a persisted login survives. Tokens are revoked by
|
||||
// deleting them from the token file, so a long window costs nothing.
|
||||
const rememberFor = 365 * 24 * time.Hour
|
||||
|
||||
@@ -39,22 +39,28 @@ func credential(r *http.Request) string {
|
||||
return cookieCredential(r)
|
||||
}
|
||||
|
||||
// remember stores the token in a cookie.
|
||||
// logIn stores the token in a cookie.
|
||||
//
|
||||
// SameSite=Strict is what makes accepting a cookie as a credential safe here:
|
||||
// without it, any site could make the browser post an upload or a deletion with
|
||||
// the cookie attached. Scoping the path to the mount point keeps the credential
|
||||
// out of requests to the rest of the host when running under a subdirectory.
|
||||
func (s *Server) remember(w http.ResponseWriter, r *http.Request, token string) {
|
||||
http.SetCookie(w, &http.Cookie{
|
||||
//
|
||||
// When persist is false the cookie carries no lifetime and the browser drops it
|
||||
// when it closes, which is the right default on a machine that is not yours.
|
||||
func (s *Server) logIn(w http.ResponseWriter, r *http.Request, token string, persist bool) {
|
||||
c := &http.Cookie{
|
||||
Name: tokenCookie,
|
||||
Value: token,
|
||||
Path: s.cfg.BasePath,
|
||||
MaxAge: int(rememberFor.Seconds()),
|
||||
HttpOnly: true,
|
||||
Secure: s.isHTTPS(r),
|
||||
SameSite: http.SameSiteStrictMode,
|
||||
})
|
||||
}
|
||||
if persist {
|
||||
c.MaxAge = int(rememberFor.Seconds())
|
||||
}
|
||||
http.SetCookie(w, c)
|
||||
}
|
||||
|
||||
// forget clears a remembered token.
|
||||
@@ -88,13 +94,3 @@ func (s *Server) isHTTPS(r *http.Request) bool {
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
// handleForget drops the remembered token and returns to the upload page.
|
||||
func (s *Server) handleForget(w http.ResponseWriter, r *http.Request) {
|
||||
s.forget(w, r)
|
||||
if wantsJSON(r) {
|
||||
writeJSON(w, http.StatusOK, map[string]string{"status": "forgotten"})
|
||||
return
|
||||
}
|
||||
http.Redirect(w, r, s.cfg.BasePath, http.StatusSeeOther)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user