login.go 2.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475
  1. // Copyright 2017 Frédéric Guillot. All rights reserved.
  2. // Use of this source code is governed by the Apache 2.0
  3. // license that can be found in the LICENSE file.
  4. package controller
  5. import (
  6. "github.com/miniflux/miniflux/logger"
  7. "github.com/miniflux/miniflux/server/cookie"
  8. "github.com/miniflux/miniflux/server/core"
  9. "github.com/miniflux/miniflux/server/ui/form"
  10. "github.com/tomasen/realip"
  11. )
  12. // ShowLoginPage shows the login form.
  13. func (c *Controller) ShowLoginPage(ctx *core.Context, request *core.Request, response *core.Response) {
  14. if ctx.IsAuthenticated() {
  15. response.Redirect(ctx.Route("unread"))
  16. return
  17. }
  18. response.HTML().Render("login", tplParams{
  19. "csrf": ctx.CSRF(),
  20. })
  21. }
  22. // CheckLogin validates the username/password and redirects the user to the unread page.
  23. func (c *Controller) CheckLogin(ctx *core.Context, request *core.Request, response *core.Response) {
  24. authForm := form.NewAuthForm(request.Request())
  25. tplParams := tplParams{
  26. "errorMessage": "Invalid username or password.",
  27. "csrf": ctx.CSRF(),
  28. }
  29. if err := authForm.Validate(); err != nil {
  30. logger.Error("[Controller:CheckLogin] %v", err)
  31. response.HTML().Render("login", tplParams)
  32. return
  33. }
  34. if err := c.store.CheckPassword(authForm.Username, authForm.Password); err != nil {
  35. logger.Error("[Controller:CheckLogin] %v", err)
  36. response.HTML().Render("login", tplParams)
  37. return
  38. }
  39. sessionToken, err := c.store.CreateUserSession(
  40. authForm.Username,
  41. request.Request().UserAgent(),
  42. realip.RealIP(request.Request()),
  43. )
  44. if err != nil {
  45. response.HTML().ServerError(err)
  46. return
  47. }
  48. logger.Info("[Controller:CheckLogin] username=%s just logged in", authForm.Username)
  49. response.SetCookie(cookie.New(cookie.CookieUserSessionID, sessionToken, request.IsHTTPS()))
  50. response.Redirect(ctx.Route("unread"))
  51. }
  52. // Logout destroy the session and redirects the user to the login page.
  53. func (c *Controller) Logout(ctx *core.Context, request *core.Request, response *core.Response) {
  54. user := ctx.LoggedUser()
  55. if err := c.store.RemoveUserSessionByToken(user.ID, ctx.UserSessionToken()); err != nil {
  56. logger.Error("[Controller:Logout] %v", err)
  57. }
  58. response.SetCookie(cookie.Expired(cookie.CookieUserSessionID, request.IsHTTPS()))
  59. response.Redirect(ctx.Route("login"))
  60. }