Feat: Implement basic web authentication and UI
This commit introduces the foundation for web-based authentication and user interface. It includes: - **Session Management**: Securely handling user sessions using cryptographically generated tokens, cookies with appropriate security flags, and server-side storage. - **Login/Logout Functionality**: Endpoints for users to log in with their credentials and log out, clearing their session. - **User Interface**: Basic templates for the login page, a list of cases, and a detailed view of a single case, allowing users to navigate and view their data. - **Authorization**: An `AuthenticatedWebUser` extractor to ensure only logged-in users can access protected web routes. - **Configuration**: Added a `cookie_secure` option to the configuration to control the `Secure` flag on session cookies, useful for local development. - **Dependencies**: Added necessary dependencies for password hashing, time handling, and TOML file manipulation. - **Helper Binary**: Included a `hash-password` binary to simplify generating bcrypt hashes for user passwords.
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
//! Generate a bcrypt hash for a plaintext password.
|
||||
//! Use when adding or rotating a `web_password` entry in `users.toml`.
|
||||
//!
|
||||
//! Dev: `cargo run --quiet --bin hash-password -- 'my-password'`
|
||||
//! Release: `./target/release/hash-password 'my-password'`
|
||||
|
||||
fn main() {
|
||||
let password = std::env::args().nth(1).unwrap_or_else(|| {
|
||||
eprintln!("Usage: hash-password '<password>'");
|
||||
std::process::exit(2);
|
||||
});
|
||||
|
||||
let hash = bcrypt::hash(&password, bcrypt::DEFAULT_COST)
|
||||
.expect("bcrypt hashing failed");
|
||||
println!("{hash}");
|
||||
}
|
||||
Reference in New Issue
Block a user