aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/handlers_auth.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/web/handlers_auth.go')
-rw-r--r--internal/web/handlers_auth.go6
1 files changed, 6 insertions, 0 deletions
diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go
index 708285d..5c57254 100644
--- a/internal/web/handlers_auth.go
+++ b/internal/web/handlers_auth.go
@@ -91,7 +91,13 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
http.Redirect(w, r, s.landing(r, u, next), http.StatusSeeOther)
}
+// handleLogout ends the session. It needs the CSRF token like every other
+// management POST, or any page could log the user out (a blog is same-site,
+// so SameSite=Lax alone would not stop it); anonymous requests just bounce.
func (s *Server) handleLogout(w http.ResponseWriter, r *http.Request) {
+ if currentUser(r) != nil && !s.guardPOST(w, r, 0) {
+ return
+ }
auth.ClearSessionCookie(w, s.cfg.HTTPS)
http.Redirect(w, r, "/webadmin", http.StatusSeeOther)
}