Encrypt cookies

This commit is contained in:
2026-09-13 11:45:15 +02:00
parent 99bdadf248
commit cb34bae784
11 changed files with 344 additions and 34 deletions
+9 -2
View File
@@ -40,7 +40,7 @@ func (s *Server) handleLoginPage(w http.ResponseWriter, r *http.Request) {
next := destination(r.URL.Query().Get("next"))
// Already logged in: say so rather than showing an empty form.
if lim, err := s.limitsFor(r, cookieCredential(r)); err == nil && !lim.Anonymous() {
if lim, err := s.limitsFor(r, s.cookieCredential(r)); err == nil && !lim.Anonymous() {
s.render(w, http.StatusOK, "login.html", loginPage{
page: s.page(r, "Log in", false),
Next: next,
@@ -82,7 +82,14 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
return
}
s.logIn(w, r, token, r.PostFormValue("persist") != "")
if err := s.logIn(w, r, token, r.PostFormValue("persist") != ""); err != nil {
// Sealing needs nothing but randomness, so this is the machine failing
// rather than the caller: say so instead of leaving them logged out
// with no explanation.
s.log.Error("sealing the session", "err", err)
s.fail(w, r, http.StatusInternalServerError, "Could not start a session.")
return
}
s.log.Info("logged in", "name", lim.Name, "ip", clientIP(r, s.cfg))
if wantsJSON(r) {