aboutsummaryrefslogtreecommitdiffstats
path: root/AGENTS.md
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 11:24:43 +0300
committergrm <grm@eyesin.space>2026-09-18 11:24:43 +0300
commitfa67ce6346fa1c49bf4c981317193b3e14653d60 (patch)
tree94841af7451d93eccaf305b940f2158c03b68830 /AGENTS.md
parentac125593efe689fabd1e48a7023249c8973698b8 (diff)
downloadblogspace-fa67ce6346fa1c49bf4c981317193b3e14653d60.tar.gz
blogspace-fa67ce6346fa1c49bf4c981317193b3e14653d60.tar.bz2
blogspace-fa67ce6346fa1c49bf4c981317193b3e14653d60.zip
Send a blogger to their own dashboard from another blog's /webadmin
Typing /webadmin on someone else's blog while logged in (or logging in from there) landed on /b/<their-sub>/ and a 403 "This is not your blog." Both login paths now go through landing(), which swaps a next that points at a blog the user cannot manage for /dashboard; superadmins keep going where they asked. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'AGENTS.md')
-rw-r--r--AGENTS.md5
1 files changed, 4 insertions, 1 deletions
diff --git a/AGENTS.md b/AGENTS.md
index 2953025..679bb64 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -115,7 +115,10 @@ internal/web/ server.go (host router, middleware, render helpers)
`/news`, `/tag/go`) — `/news/?p=2` would be a 404.
- **Auth**: login lives only at `/webadmin` on the root domain (deliberately
not `/login`, and not linked from public pages); `/webadmin` on a blog host
- redirects there with `next=/b/<sub>/`. HS256 JWT in `session` cookie (`HttpOnly`, `SameSite=Lax`,
+ redirects there with `next=/b/<sub>/`. After login (or when already logged
+ in) `landing` sends a blogger whose `next` is another blog's `/b/<sub>/…`
+ to `/dashboard` (their own blog) instead of the 403; superadmins go where
+ they asked. HS256 JWT in `session` cookie (`HttpOnly`, `SameSite=Lax`,
7 days). Claims carry `uid` + `ver` (= `users.token_version`); the
session middleware re-loads the user every request and drops the session
if disabled or version mismatch. Password change / reset / disable bump