summaryrefslogtreecommitdiff
path: root/src/cli.rs
diff options
context:
space:
mode:
authorOwen Jacobson <owen@grimoire.ca>2024-09-04 11:00:48 -0400
committerOwen Jacobson <owen@grimoire.ca>2024-09-04 11:00:48 -0400
commit4259e7406aec128bfb45fbb46eefa501f12870da (patch)
tree876277de0211d2cdfbe9a21ba2f84b14829b1e5f /src/cli.rs
parent636d5ff79a45c33d27f62b99edc905b847750ac1 (diff)
Login fixes:
1. Stop rejecting login attempts when there's an identity cookie already set. This looked like a good idea, but in practice it's not a sufficient check, as it doesnt' ensure the identity cookie is actually valid. Validating it is an option, but the do-nothing alternative (which I went with) is that a login request while already logged in overwrites your identity cookie, instead. It's less code, semantically not bonkers, and doesn't _appear_ to introduce any interesting user security issues. 2. Redirect to / after successful login/logout, instead of dropping the user on a useless text page.
Diffstat (limited to 'src/cli.rs')
0 files changed, 0 insertions, 0 deletions