aboutsummaryrefslogtreecommitdiffstats
path: root/AGENTS.md
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-12 12:15:47 +0300
committergrm <grm@eyesin.space>2026-09-12 12:15:47 +0300
commit3073532f723b976a2f54666f779e9a045bacb7f6 (patch)
tree442181bd2b5ac48a2ec5621203f81e64cb1769c5 /AGENTS.md
parentf82c2256d619e92cf0e928deb3b23b735071aaf3 (diff)
downloadblogspace-3073532f723b976a2f54666f779e9a045bacb7f6.tar.gz
blogspace-3073532f723b976a2f54666f779e9a045bacb7f6.tar.bz2
blogspace-3073532f723b976a2f54666f779e9a045bacb7f6.zip
Rename /login to /webadmin and reach it from every blog
The login URL is less guessable, bloggers can type /webadmin on their own blog and get bounced to the root login page (and back to their dashboard after logging in), and the public root blog no longer advertises the admin entry point in its footer. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'AGENTS.md')
-rw-r--r--AGENTS.md6
1 files changed, 4 insertions, 2 deletions
diff --git a/AGENTS.md b/AGENTS.md
index 9c45974..cfe3d06 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -7,7 +7,7 @@ the same commit. It is the first thing a future session reads.
## What this is
Blogspace: a multi-tenant blog host. One Go binary + Postgres. The base domain
-serves the superadmin's own blog plus the management site (`/login`,
+serves the superadmin's own blog plus the management site (`/webadmin`,
`/dashboard`, `/b/<sub>/…`, `/admin/`); every other blog is served at
`<sub>.BASE_DOMAIN`. See `README.md` for the user-facing description, config
table and deployment notes.
@@ -62,7 +62,9 @@ internal/web/ server.go (host router, middleware, render helpers)
(`handlers_pages.go`) and to `TestRootRoutePrecedence`. `/static/{file}`
is a single segment on purpose (a `/static/` prefix pattern conflicts
with `/{page}/{post}`); static files must stay flat.
-- **Auth**: HS256 JWT in `session` cookie (`HttpOnly`, `SameSite=Lax`,
+- **Auth**: login lives only at `/webadmin` on the root domain (deliberately
+ not `/login`, and not linked from public pages); `/webadmin` on a blog host
+ redirects there with `next=/b/<sub>/`. HS256 JWT in `session` cookie (`HttpOnly`, `SameSite=Lax`,
7 days). Claims carry `uid` + `ver` (= `users.token_version`); the
session middleware re-loads the user every request and drops the session
if disabled or version mismatch. Password change / reset / disable bump