From 3073532f723b976a2f54666f779e9a045bacb7f6 Mon Sep 17 00:00:00 2001 From: grm Date: Sat, 12 Sep 2026 12:15:47 +0300 Subject: Rename /login to /webadmin and reach it from every blog The login URL is less guessable, bloggers can type /webadmin on their own blog and get bounced to the root login page (and back to their dashboard after logging in), and the public root blog no longer advertises the admin entry point in its footer. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- internal/web/handlers_auth.go | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) (limited to 'internal/web/handlers_auth.go') diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go index 5d82ead..7c1d1e8 100644 --- a/internal/web/handlers_auth.go +++ b/internal/web/handlers_auth.go @@ -11,11 +11,22 @@ import ( ) func (s *Server) handleLoginForm(w http.ResponseWriter, r *http.Request) { + next := safeNext(r.URL.Query().Get("next")) if currentUser(r) != nil { - http.Redirect(w, r, "/dashboard", http.StatusSeeOther) + if next == "" { + next = "/dashboard" + } + http.Redirect(w, r, next, http.StatusSeeOther) return } - s.render(w, r, "auth/login.html", map[string]any{"next": safeNext(r.URL.Query().Get("next"))}) + s.render(w, r, "auth/login.html", map[string]any{"next": next}) +} + +// handleWebadminRedirect serves /webadmin on a blog's own host: the login page +// lives on the root domain, so bounce there and come back to this blog's dashboard. +func (s *Server) handleWebadminRedirect(w http.ResponseWriter, r *http.Request) { + sub, _ := r.Context().Value(ctxHostSub).(string) + http.Redirect(w, r, s.cfg.RootURL()+"/webadmin?next="+urlQuery("/b/"+sub+"/"), http.StatusSeeOther) } func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { @@ -54,7 +65,7 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) { func (s *Server) handleLogout(w http.ResponseWriter, r *http.Request) { auth.ClearSessionCookie(w) - http.Redirect(w, r, "/login", http.StatusSeeOther) + http.Redirect(w, r, "/webadmin", http.StatusSeeOther) } func (s *Server) handleDashboard(w http.ResponseWriter, r *http.Request) { -- cgit v1.2.3