Add member accounts: invites, registration, login, sessions, ban
Step 2 of the build order. The admin mints an invite link, the recipient registers with it, and from then on has a session. - The invite is spent in the same transaction that creates the account, so a failed signup leaves the code usable - Sessions are idle timeouts, 24h or 30 days with remember me, read from a cookie or a bearer header, extended at most once a minute - Ban is a reversible toggle that drops the member's live sessions - No password minimum; login is rate limited instead, 10 failures per email in 15 minutes, cleared by a correct password - Invite codes render as links carrying ?code=, which the register form prefills; PUBLIC_URL makes them pasteable from the loopback admin panel Tests cover invite spending, the idle timeout, ban, and the rate limiter.
This commit is contained in:
@@ -0,0 +1,25 @@
|
||||
{{define "content"}}
|
||||
<h1>Liity</h1>
|
||||
|
||||
<form method="post" action="/register" class="stack">
|
||||
<label>Kutsukoodi
|
||||
<input name="code" value="{{.Data.Code}}" required>
|
||||
{{with .Data.Errors.code}}<span class="error">{{.}}</span>{{end}}
|
||||
</label>
|
||||
<label>Nimi
|
||||
<input name="name" value="{{.Data.Name}}" required maxlength="50">
|
||||
{{with .Data.Errors.name}}<span class="error">{{.}}</span>{{end}}
|
||||
</label>
|
||||
<label>Sähköposti
|
||||
<input type="email" name="email" value="{{.Data.Email}}" required autocomplete="email">
|
||||
{{with .Data.Errors.email}}<span class="error">{{.}}</span>{{end}}
|
||||
</label>
|
||||
<label>Salasana
|
||||
<input type="password" name="password" required autocomplete="new-password">
|
||||
{{with .Data.Errors.password}}<span class="error">{{.}}</span>{{end}}
|
||||
</label>
|
||||
<button type="submit">Liity</button>
|
||||
</form>
|
||||
|
||||
<p class="muted">Sähköpostiosoite on kirjautumistunnuksesi. Levyraati ei lähetä sähköpostia.</p>
|
||||
{{end}}
|
||||
Reference in New Issue
Block a user