aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web
diff options
context:
space:
mode:
Diffstat (limited to 'internal/web')
-rw-r--r--internal/web/handlers_auth.go6
-rw-r--r--internal/web/web_test.go12
2 files changed, 18 insertions, 0 deletions
diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go
index 708285d..5c57254 100644
--- a/internal/web/handlers_auth.go
+++ b/internal/web/handlers_auth.go
@@ -91,7 +91,13 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
http.Redirect(w, r, s.landing(r, u, next), http.StatusSeeOther)
}
+// handleLogout ends the session. It needs the CSRF token like every other
+// management POST, or any page could log the user out (a blog is same-site,
+// so SameSite=Lax alone would not stop it); anonymous requests just bounce.
func (s *Server) handleLogout(w http.ResponseWriter, r *http.Request) {
+ if currentUser(r) != nil && !s.guardPOST(w, r, 0) {
+ return
+ }
auth.ClearSessionCookie(w, s.cfg.HTTPS)
http.Redirect(w, r, "/webadmin", http.StatusSeeOther)
}
diff --git a/internal/web/web_test.go b/internal/web/web_test.go
index 7f66085..74c0fb7 100644
--- a/internal/web/web_test.go
+++ b/internal/web/web_test.go
@@ -1014,3 +1014,15 @@ func TestSafeNext(t *testing.T) {
}
}
}
+
+// Logging out while not logged in just goes to the login page (nothing to protect).
+func TestLogoutAnonymous(t *testing.T) {
+ s := NewServer(&config.Config{BaseDomain: "example.com", JWTSecret: []byte("x")}, nil)
+ rec := httptest.NewRecorder()
+ req := httptest.NewRequest("POST", "/logout", nil)
+ req.Host = "example.com"
+ s.ServeHTTP(rec, req)
+ if rec.Code != http.StatusSeeOther || rec.Header().Get("Location") != "/webadmin" {
+ t.Errorf("got %d → %q", rec.Code, rec.Header().Get("Location"))
+ }
+}