aboutsummaryrefslogtreecommitdiffhomepage
path: root/server/ui/controller/login.go
blob: 2571f6efa6a999ce823221d0a63860dfbd8cfa72 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
// Copyright 2017 Frédéric Guillot. All rights reserved.
// Use of this source code is governed by the Apache 2.0
// license that can be found in the LICENSE file.

package controller

import (
	"log"
	"net/http"
	"time"

	"github.com/miniflux/miniflux2/server/core"
	"github.com/miniflux/miniflux2/server/ui/form"

	"github.com/tomasen/realip"
)

// ShowLoginPage shows the login form.
func (c *Controller) ShowLoginPage(ctx *core.Context, request *core.Request, response *core.Response) {
	if ctx.IsAuthenticated() {
		response.Redirect(ctx.Route("unread"))
		return
	}

	response.HTML().Render("login", tplParams{
		"csrf": ctx.CsrfToken(),
	})
}

// CheckLogin validates the username/password and redirects the user to the unread page.
func (c *Controller) CheckLogin(ctx *core.Context, request *core.Request, response *core.Response) {
	authForm := form.NewAuthForm(request.Request())
	tplParams := tplParams{
		"errorMessage": "Invalid username or password.",
		"csrf":         ctx.CsrfToken(),
	}

	if err := authForm.Validate(); err != nil {
		log.Println(err)
		response.HTML().Render("login", tplParams)
		return
	}

	if err := c.store.CheckPassword(authForm.Username, authForm.Password); err != nil {
		log.Println(err)
		response.HTML().Render("login", tplParams)
		return
	}

	sessionToken, err := c.store.CreateSession(
		authForm.Username,
		request.Request().UserAgent(),
		realip.RealIP(request.Request()),
	)

	if err != nil {
		response.HTML().ServerError(err)
		return
	}

	log.Printf("[UI:CheckLogin] username=%s just logged in\n", authForm.Username)

	cookie := &http.Cookie{
		Name:     "sessionID",
		Value:    sessionToken,
		Path:     "/",
		Secure:   request.IsHTTPS(),
		HttpOnly: true,
	}

	response.SetCookie(cookie)
	response.Redirect(ctx.Route("unread"))
}

// Logout destroy the session and redirects the user to the login page.
func (c *Controller) Logout(ctx *core.Context, request *core.Request, response *core.Response) {
	user := ctx.LoggedUser()

	sessionCookie := request.Cookie("sessionID")
	if err := c.store.RemoveSessionByToken(user.ID, sessionCookie); err != nil {
		log.Printf("[UI:Logout] %v", err)
	}

	cookie := &http.Cookie{
		Name:     "sessionID",
		Value:    "",
		Path:     "/",
		Secure:   request.IsHTTPS(),
		HttpOnly: true,
		MaxAge:   -1,
		Expires:  time.Date(1970, 1, 1, 0, 0, 0, 0, time.UTC),
	}

	response.SetCookie(cookie)
	response.Redirect(ctx.Route("login"))
}