<feed xmlns='http://www.w3.org/2005/Atom'>
<title>blogspace/internal/web/handlers_auth.go, branch master</title>
<subtitle>blogspace</subtitle>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/'/>
<entry>
<title>Security: Refuse form posts a browser marks as coming from another origin</title>
<updated>2026-09-18T10:48:50+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T10:48:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=abc1898daebae33405688618caffa01cece3b850'/>
<id>abc1898daebae33405688618caffa01cece3b850</id>
<content type='text'>
Every blog is a subdomain of the root domain, which makes a blog page
"same-site" to the dashboard: SameSite=Lax sends the session cookie
with a form a blog's custom HTML submits to example.com. The HMAC token
already stops those, but the login form had nothing (login CSRF), and
a second, independent check costs one header lookup. A POST whose
Sec-Fetch-Site is cross-site or same-site is now refused in guardPOST
and on login; old browsers without the header keep working under the
token alone.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Every blog is a subdomain of the root domain, which makes a blog page
"same-site" to the dashboard: SameSite=Lax sends the session cookie
with a form a blog's custom HTML submits to example.com. The HMAC token
already stops those, but the login form had nothing (login CSRF), and
a second, independent check costs one header lookup. A POST whose
Sec-Fetch-Site is cross-site or same-site is now refused in guardPOST
and on login; old browsers without the header keep working under the
token alone.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Security: Check the CSRF token on logout</title>
<updated>2026-09-18T10:48:27+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T10:48:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=526a8742688ed58ae40ba1f254c2e7f1f7bbd866'/>
<id>526a8742688ed58ae40ba1f254c2e7f1f7bbd866</id>
<content type='text'>
/logout was the one management POST without the token. A blog lives on
a subdomain of the root domain, which is same-site, so SameSite=Lax
does not keep the cookie off a form a blog page submits: any blogger's
custom HTML could log the superadmin out at will. The logout form
already carried _csrf; the handler now checks it through guardPOST.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
/logout was the one management POST without the token. A blog lives on
a subdomain of the root domain, which is same-site, so SameSite=Lax
does not keep the cookie off a form a blog page submits: any blogger's
custom HTML could log the superadmin out at will. The logout form
already carried _csrf; the handler now checks it through guardPOST.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Security: Reject backslashes in post-login redirect targets</title>
<updated>2026-09-18T10:48:02+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T10:48:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=d71a01f4fcc4bb5ca040889694c94a07e52fa50e'/>
<id>d71a01f4fcc4bb5ca040889694c94a07e52fa50e</id>
<content type='text'>
safeNext only refused a second leading slash, but browsers treat
"/\evil.com" as "//evil.com", so ?next= was still an open redirect
after login. No path of ours contains a backslash, so any one is refused.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
safeNext only refused a second leading slash, but browsers treat
"/\evil.com" as "//evil.com", so ?next= was still an open redirect
after login. No path of ours contains a backslash, so any one is refused.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Security: Add HTTPS and TRUST_PROXY settings</title>
<updated>2026-09-18T10:47:49+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T10:47:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=3eeaa6d9a33f9294ade64c8ff26144fba86a379e'/>
<id>3eeaa6d9a33f9294ade64c8ff26144fba86a379e</id>
<content type='text'>
The app only ever speaks plain HTTP, so it could not know the site was
served over TLS: generated links were http:// (the /webadmin bounce
from a blog host sent the login page over http), the session cookie
was never Secure and nothing sent HSTS. HTTPS=true fixes all three;
ClearSessionCookie now uses the same attributes as the set, since a
browser only replaces a cookie whose Secure flag matches.

TRUST_PROXY=true makes the client address the last X-Forwarded-For
entry — the one our proxy appended — so throttling and the log see
real addresses instead of the proxy's; earlier entries are whatever
the client sent and are ignored. Production startup warns when HTTPS
is off.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The app only ever speaks plain HTTP, so it could not know the site was
served over TLS: generated links were http:// (the /webadmin bounce
from a blog host sent the login page over http), the session cookie
was never Secure and nothing sent HSTS. HTTPS=true fixes all three;
ClearSessionCookie now uses the same attributes as the set, since a
browser only replaces a cookie whose Secure flag matches.

TRUST_PROXY=true makes the client address the last X-Forwarded-For
entry — the one our proxy appended — so throttling and the log see
real addresses instead of the proxy's; earlier entries are whatever
the client sent and are ignored. Production startup warns when HTTPS
is off.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Security: Cap the login body and log failed logins</title>
<updated>2026-09-18T10:46:33+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T10:46:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=254733b0566830a46e5a44c2d3127f57bfaceb65'/>
<id>254733b0566830a46e5a44c2d3127f57bfaceb65</id>
<content type='text'>
POST /webadmin is the one form outside guardPOST, so nothing bounded
its body: a multipart login could park 32 MB in memory or temp files
per request. It now reads at most 64 KB. Wrong passwords are logged
with the username and client address so an attack shows up in the log
(fail2ban can read it) instead of being invisible.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
POST /webadmin is the one form outside guardPOST, so nothing bounded
its body: a multipart login could park 32 MB in memory or temp files
per request. It now reads at most 64 KB. Wrong passwords are logged
with the username and client address so an attack shows up in the log
(fail2ban can read it) instead of being invisible.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Security: Throttle login attempts with a per-address, per-account token bucket</title>
<updated>2026-09-18T10:46:11+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T10:46:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=f8d90e3d80ec798689be5fdf792e6c1401ad748f'/>
<id>f8d90e3d80ec798689be5fdf792e6c1401ad748f</id>
<content type='text'>
Nothing stopped a bot from trying passwords against /webadmin as fast
as bcrypt would go. A small in-memory limiter (stdlib only, one
process) now refuses a login with 429 once an address, or an account,
has made ten attempts, and lets one more through every six seconds;
keying on both means many addresses guessing one account are throttled
too. Refusals are logged.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Nothing stopped a bot from trying passwords against /webadmin as fast
as bcrypt would go. A small in-memory limiter (stdlib only, one
process) now refuses a login with 429 once an address, or an account,
has made ten attempts, and lets one more through every six seconds;
keying on both means many addresses guessing one account are throttled
too. Refusals are logged.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Send a blogger to their own dashboard from another blog's /webadmin</title>
<updated>2026-09-18T08:24:43+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T08:24:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=fa67ce6346fa1c49bf4c981317193b3e14653d60'/>
<id>fa67ce6346fa1c49bf4c981317193b3e14653d60</id>
<content type='text'>
Typing /webadmin on someone else's blog while logged in (or logging in
from there) landed on /b/&lt;their-sub&gt;/ and a 403 "This is not your blog."
Both login paths now go through landing(), which swaps a next that points
at a blog the user cannot manage for /dashboard; superadmins keep going
where they asked.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Typing /webadmin on someone else's blog while logged in (or logging in
from there) landed on /b/&lt;their-sub&gt;/ and a 403 "This is not your blog."
Both login paths now go through landing(), which swaps a next that points
at a blog the user cannot manage for /dashboard; superadmins keep going
where they asked.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Add languages: English and Greek, chosen per blog on the Settings tab</title>
<updated>2026-09-13T22:32:25+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-13T22:32:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=e14a4250efb828262347f5a4bbc4067cd71d885f'/>
<id>e14a4250efb828262347f5a4bbc4067cd71d885f</id>
<content type='text'>
Every blog and its dashboard were hard-wired to English. A blogger can
now pick the language of their blog; it switches the whole dashboard and
the blog's fixed text — post dates, archive months, the RSS link, the
pager, the 404 page — while what the blogger wrote is left alone.

The new internal/i18n package keys translations by the English string,
so an untranslated key renders as English rather than blank, and
TestGreekCatalogComplete scans the templates and handlers to fail when
the Greek catalog misses a key or keeps a stale one. Templates are
compiled once per language with t/tf/date/postdate/month closed over the
language, so they need no data plumbing.

The language lives in settings.language (blog migration 00002), not in
the theme, so "Reset design" does not touch it. Public pages use the
blog's language; management pages use the logged-in user's own blog's,
so a superadmin editing someone else's blog keeps theirs; the login page
follows Accept-Language.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Every blog and its dashboard were hard-wired to English. A blogger can
now pick the language of their blog; it switches the whole dashboard and
the blog's fixed text — post dates, archive months, the RSS link, the
pager, the 404 page — while what the blogger wrote is left alone.

The new internal/i18n package keys translations by the English string,
so an untranslated key renders as English rather than blank, and
TestGreekCatalogComplete scans the templates and handlers to fail when
the Greek catalog misses a key or keeps a stale one. Templates are
compiled once per language with t/tf/date/postdate/month closed over the
language, so they need no data plumbing.

The language lives in settings.language (blog migration 00002), not in
the theme, so "Reset design" does not touch it. Public pages use the
blog's language; management pages use the logged-in user's own blog's,
so a superadmin editing someone else's blog keeps theirs; the login page
follows Accept-Language.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Rename /login to /webadmin and reach it from every blog</title>
<updated>2026-09-12T09:15:47+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-12T09:15:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=3073532f723b976a2f54666f779e9a045bacb7f6'/>
<id>3073532f723b976a2f54666f779e9a045bacb7f6</id>
<content type='text'>
The login URL is less guessable, bloggers can type /webadmin on their own
blog and get bounced to the root login page (and back to their dashboard
after logging in), and the public root blog no longer advertises the
admin entry point in its footer.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The login URL is less guessable, bloggers can type /webadmin on their own
blog and get bounced to the root login page (and back to their dashboard
after logging in), and the public root blog no longer advertises the
admin entry point in its footer.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Serve the superadmin's blog on the root domain</title>
<updated>2026-09-12T08:43:14+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-12T08:43:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=f0eaf46755e04b806e2df07a2fabd4060a72d54c'/>
<id>f0eaf46755e04b806e2df07a2fabd4060a72d54c</id>
<content type='text'>
The base domain (and www.) now serves a regular blog owned by the first
superadmin, created automatically on startup, alongside the management
routes. Literal management paths take precedence over the blog's page
wildcards, and the slugs they would shadow are reserved.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The base domain (and www.) now serves a regular blog owned by the first
superadmin, created automatically on startup, alongside the management
routes. Literal management paths take precedence over the blog's page
wildcards, and the slugs they would shadow are reserved.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
</feed>
