Authentication (#22)
* Authorization added
* added secret to password, md5 hashing, removed promise from verifyToken, deleted links when not authorized
* added dbinsert script
* turned verifyToken to middleware, added description for dbinsert, added hidden csrf field in auth form
* added middlewares, user model and controller
* JSDoc fix
* wrong password processing fix
* added comments to dbinsert script, moved salt and passHash to singe db doc
* Moved salt to .env, upgradedscript for generating password was, fixed comments and JSDoc
* Deleted using salt (now user is only one), changed verifying password to bcrypt.compare, added httpyOnly property to jwt cookie
2019-03-06 13:22:57 +03:00
|
|
|
{% extends 'layout.twig' %}
|
|
|
|
|
|
|
|
{% block body %}
|
2019-03-13 12:25:43 +03:00
|
|
|
<form class="auth-form" method="post" action="/auth">
|
|
|
|
<h1>
|
|
|
|
┬┴┬┴┤ ͜ʖ ͡°) ├┬┴┬┴
|
|
|
|
</h1>
|
|
|
|
<p>
|
|
|
|
Enter a password to access pages editing
|
|
|
|
</p>
|
2022-04-22 23:28:40 +03:00
|
|
|
<p>
|
|
|
|
{{ header }}
|
|
|
|
</p>
|
2020-07-27 20:42:37 +03:00
|
|
|
<input type="hidden" name="_csrf" value={{ csrfToken }}>
|
Authentication (#22)
* Authorization added
* added secret to password, md5 hashing, removed promise from verifyToken, deleted links when not authorized
* added dbinsert script
* turned verifyToken to middleware, added description for dbinsert, added hidden csrf field in auth form
* added middlewares, user model and controller
* JSDoc fix
* wrong password processing fix
* added comments to dbinsert script, moved salt and passHash to singe db doc
* Moved salt to .env, upgradedscript for generating password was, fixed comments and JSDoc
* Deleted using salt (now user is only one), changed verifying password to bcrypt.compare, added httpyOnly property to jwt cookie
2019-03-06 13:22:57 +03:00
|
|
|
<input type="password" name="password" placeholder="Password">
|
2019-03-13 12:25:43 +03:00
|
|
|
<input type="submit" value="Login">
|
Authentication (#22)
* Authorization added
* added secret to password, md5 hashing, removed promise from verifyToken, deleted links when not authorized
* added dbinsert script
* turned verifyToken to middleware, added description for dbinsert, added hidden csrf field in auth form
* added middlewares, user model and controller
* JSDoc fix
* wrong password processing fix
* added comments to dbinsert script, moved salt and passHash to singe db doc
* Moved salt to .env, upgradedscript for generating password was, fixed comments and JSDoc
* Deleted using salt (now user is only one), changed verifying password to bcrypt.compare, added httpyOnly property to jwt cookie
2019-03-06 13:22:57 +03:00
|
|
|
</form>
|
|
|
|
{% endblock %}
|
|
|
|
|