diff options
Diffstat (limited to 'internal/web/handlers_auth.go')
| -rw-r--r-- | internal/web/handlers_auth.go | 12 |
1 files changed, 6 insertions, 6 deletions
diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go index 69b7b98..6c76d81 100644 --- a/internal/web/handlers_auth.go +++ b/internal/web/handlers_auth.go @@ -63,7 +63,7 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { } // Both buckets must have a token: one address guessing many accounts and // many addresses guessing one account are throttled alike. - if !s.throttle(w, r, s.loginLimit, "ip:"+clientIP(r)) || !s.throttle(w, r, s.loginLimit, "user:"+strings.ToLower(username)) { + if !s.throttle(w, r, s.loginLimit, "ip:"+s.clientIP(r)) || !s.throttle(w, r, s.loginLimit, "user:"+strings.ToLower(username)) { return } u, err := s.st.UserByUsername(r.Context(), username) @@ -73,12 +73,12 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { return } auth.CheckPassword("$2a$10$invalidinvalidinvalidinvalidinvalidinvalidinvalidinval", password) // constant-ish time - logf("login failed for %q from %s", username, clientIP(r)) + logf("login failed for %q from %s", username, s.clientIP(r)) fail() return } if u.Disabled || !auth.CheckPassword(u.PasswordHash, password) { - logf("login failed for %q from %s", username, clientIP(r)) + logf("login failed for %q from %s", username, s.clientIP(r)) fail() return } @@ -87,12 +87,12 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { s.serverError(w, err) return } - auth.SetSessionCookie(w, tok) + auth.SetSessionCookie(w, tok, s.cfg.HTTPS) http.Redirect(w, r, s.landing(r, u, next), http.StatusSeeOther) } func (s *Server) handleLogout(w http.ResponseWriter, r *http.Request) { - auth.ClearSessionCookie(w) + auth.ClearSessionCookie(w, s.cfg.HTTPS) http.Redirect(w, r, "/webadmin", http.StatusSeeOther) } @@ -149,7 +149,7 @@ func (s *Server) handlePassword(w http.ResponseWriter, r *http.Request) { s.serverError(w, err) return } - auth.SetSessionCookie(w, tok) + auth.SetSessionCookie(w, tok, s.cfg.HTTPS) redirectOK(w, r, "/dashboard", s.tr(r, "Password changed.")) } |
