diff options
Diffstat (limited to 'internal/web/handlers_auth.go')
| -rw-r--r-- | internal/web/handlers_auth.go | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go index 708285d..5c57254 100644 --- a/internal/web/handlers_auth.go +++ b/internal/web/handlers_auth.go @@ -91,7 +91,13 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { http.Redirect(w, r, s.landing(r, u, next), http.StatusSeeOther) } +// handleLogout ends the session. It needs the CSRF token like every other +// management POST, or any page could log the user out (a blog is same-site, +// so SameSite=Lax alone would not stop it); anonymous requests just bounce. func (s *Server) handleLogout(w http.ResponseWriter, r *http.Request) { + if currentUser(r) != nil && !s.guardPOST(w, r, 0) { + return + } auth.ClearSessionCookie(w, s.cfg.HTTPS) http.Redirect(w, r, "/webadmin", http.StatusSeeOther) } |
