Skip to content

v0.1.3

Choose a tag to compare

@Neotoxic-off Neotoxic-off released this 17 May 00:59
· 2 commits to master since this release
Add admin login/logout and auth proxy

Introduces a simple session-based admin auth flow and middleware to protect the app.

- Adds POST /api/auth/login: validates the provided password against ADMIN_PASSWORD, sets an httpOnly `stash_session` cookie (HMAC-SHA256 hex of a fixed nonce) on success, returns 403 on invalid credentials and 500 if ADMIN_PASSWORD is not configured.
- Adds POST /api/auth/logout: clears the `stash_session` cookie.
- Adds a client-side login page at /login with form, loading/error states, and navigation on success.
- Adds a proxy middleware (web/src/proxy.ts) that redirects unauthenticated requests to /login, skips static assets and public routes (/login, /api/auth/login, /api/auth/logout), and treats missing ADMIN_PASSWORD as open access.
- Updates Navbar to include a logout button that calls the logout endpoint and navigates to the login page.

This provides basic admin protection for the app; session tokens are derived from the admin password using an HMAC-based scheme and stored in a cookie with Lax sameSite and a 7-day expiry.