ContributingWeb client
Sign-in and the session
The app asks the server for the auth status, then shows the setup page, the login page or the dashboard.
The app first asks GET /api/v1/auth/status.
1 / 4
What the status says
GET /api/v1/auth/status gives two answers:
- Does the server still need its account? If yes, the app shows
/setup. - Is this browser signed in? If not, the app shows
/login.
What the app knows
The sign-in sets the session cookie. The cookie is HttpOnly: no script can read it.
Thus src/stores/auth.ts knows only two facts: if a session exists, and who the account is.
Where the pages are
The pages are in src/pages/login/. /cli-login is there too: this page approves a ferry login.
Sessions describes the cookie from the side of the server.