diff options
| author | grm <grm@eyesin.space> | 2026-09-12 12:15:47 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-12 12:15:47 +0300 |
| commit | 3073532f723b976a2f54666f779e9a045bacb7f6 (patch) | |
| tree | 442181bd2b5ac48a2ec5621203f81e64cb1769c5 /README.md | |
| parent | f82c2256d619e92cf0e928deb3b23b735071aaf3 (diff) | |
| download | blogspace-3073532f723b976a2f54666f779e9a045bacb7f6.tar.gz blogspace-3073532f723b976a2f54666f779e9a045bacb7f6.tar.bz2 blogspace-3073532f723b976a2f54666f779e9a045bacb7f6.zip | |
Rename /login to /webadmin and reach it from every blog
The login URL is less guessable, bloggers can type /webadmin on their own
blog and get bounced to the root login page (and back to their dashboard
after logging in), and the public root blog no longer advertises the
admin entry point in its footer.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 12 |
1 files changed, 7 insertions, 5 deletions
@@ -23,8 +23,9 @@ make seed # (another terminal) demo data: superadmin admin/admin, blogger al Then open: -- Root blog (the superadmin's): http://blogspace.localhost:8080 — "Log in" link in its footer -- Dashboard: http://blogspace.localhost:8080/login (log in as `admin` or `alice`) +- Root blog (the superadmin's): http://blogspace.localhost:8080 +- Dashboard: http://blogspace.localhost:8080/webadmin (log in as `admin` or `alice`). + `/webadmin` on any blog (e.g. http://alice.blogspace.localhost:8080/webadmin) redirects here too. - Alice's blog: http://alice.blogspace.localhost:8080 Chrome and Firefox resolve any `*.localhost` name to your machine, so no DNS or @@ -103,14 +104,15 @@ internal/web/ host router, handlers, templates, static CSS, theme ### How requests are routed -`Host == BASE_DOMAIN` (or `www.`) → management site (`/login`, `/dashboard`, `/b/<sub>/…`, `/admin/`) +`Host == BASE_DOMAIN` (or `www.`) → management site (`/webadmin`, `/dashboard`, `/b/<sub>/…`, `/admin/`) **plus** the root blog's public pages on every other path. -`Host == <sub>.BASE_DOMAIN` → that blog's public pages (`/`, `/<page>`, `/<page>/<post>`, `/feed.xml`, `/media/<id>`). +`Host == <sub>.BASE_DOMAIN` → that blog's public pages (`/`, `/<page>`, `/<page>/<post>`, `/feed.xml`, `/media/<id>`), +plus `/webadmin`, which redirects to the login page on the base domain. Anything else → 404. The root blog is a normal `blogs` row with subdomain `www`; it is created on first start for the first superadmin and managed at `/b/www/`. Page slugs that would be -shadowed by management routes (`login`, `admin`, `b`, …) are rejected for every blog. +shadowed by management routes (`webadmin`, `admin`, `b`, …) are rejected for every blog. ### Auth notes |
