Sign in through the admin app instead of this one
The frontend half of the calendar auth cutover (step 4 of docs/calendar-auth-migration.md in the API repo). This app now shares one identity with the tickets, feedback and admin apps. Every call carries the session cookie via withCredentials rather than appending sessionId/sessionKey to the URL, so there is no credential left in api.service.ts at all - that was DEFERRED_SECURITY.md item 1. The login and registration forms are gone. Accounts exist only by invitation from the admin app, so both were one redirect; sign-out ends the session for all four apps and returns here, so doing it by accident costs one click. 401 and 403 are deliberately not collapsed. Only 401 goes to the login page: redirecting on 403 produces a loop where signing in succeeds and lands straight back on the refusal, and doing it for an unreachable API produces the same loop with no way out. Both of those now render a message instead. src/app/models/session.ts and the unrouted LoginComponent are dead but left in place; removing files is a separate decision. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,27 +1,25 @@
|
||||
<div *ngIf="!isLoggedIn" class="form-container">
|
||||
<p>Please log in:</p>
|
||||
<label for="email">Your @nachklang.art email: </label>
|
||||
<input id="email" type="text" aria-label="Your Email" [(ngModel)]="email"><br>
|
||||
<label for="password">Password: </label>
|
||||
<input id="password" type="password" aria-label="Password" (keyup.enter)="login()" [(ngModel)]="password"><br>
|
||||
<button (click)="login()">Login</button>
|
||||
<br><br>
|
||||
<p>If you dont' have an account yet, please use the following form to register:</p>
|
||||
<label for="name">Your full name: </label>
|
||||
<input id="name" type="text" aria-label="Your Name" [(ngModel)]="name"><br>
|
||||
<label for="registerEmail">Your @nachklang.art email: </label>
|
||||
<input id="registerEmail" type="text" aria-label="Your Email" [(ngModel)]="registerEmail"><br>
|
||||
<label for="registerPassword">Password: </label>
|
||||
<input id="registerPassword" type="password" aria-label="Password" [(ngModel)]="registerPassword"><br>
|
||||
<label for="registerPasswordConfirm">Confirm password: </label>
|
||||
<input id="registerPasswordConfirm" type="password" aria-label="Password" (keyup.enter)="register()" [(ngModel)]="registerPasswordConfirm"><br>
|
||||
<p *ngIf="!checkPasswordPolicy()">Passwords have to use uppercase and lowercase letters, numbers and must have at least 12 characters!</p>
|
||||
<p *ngIf="!checkPasswordsMatch()">Passwords do not match!</p>
|
||||
<button (click)="register()">Register</button>
|
||||
<!--
|
||||
No sign-in form and no registration form: accounts live in the admin app and
|
||||
the session is one cookie shared by all four apps. What is left here is a
|
||||
link to the right place, plus the two states that must not turn into a
|
||||
redirect loop - see `failure` in the component.
|
||||
-->
|
||||
<div *ngIf="!isLoggedIn && failure === null" class="form-container">
|
||||
<p>Signing you in…</p>
|
||||
<button (click)="signIn()">Go to sign-in</button>
|
||||
</div>
|
||||
<div *ngIf="isLoggedIn">
|
||||
<div *ngIf="failure === 'denied'" class="form-container">
|
||||
<p>This account does not have access to the calendar.</p>
|
||||
<p>Ask an administrator to grant it in the admin app, then reload.</p>
|
||||
<button (click)="reload()">Reload</button>
|
||||
<button (click)="logout()">Sign out</button>
|
||||
</div>
|
||||
<div *ngIf="failure === 'unavailable'" class="form-container">
|
||||
<p>The administration service cannot be reached right now.</p>
|
||||
<button (click)="reload()">Reload</button>
|
||||
</div>
|
||||
<div *ngIf="isLoggedIn && failure === null">
|
||||
<span>Logged in as {{getUserName()}}</span>
|
||||
<span *ngIf="checkUserInactive()"> (inactive)</span>
|
||||
<span> </span>
|
||||
<button (click)="logout()">Logout</button>
|
||||
<span> | </span>
|
||||
|
||||
Reference in New Issue
Block a user