diff --git a/auth.go b/auth.go index 0516759..e4bbc77 100644 --- a/auth.go +++ b/auth.go @@ -96,9 +96,10 @@ func handleLogin(w http.ResponseWriter, r *http.Request) error { func startSession(w http.ResponseWriter, r *http.Request, uid int64) error { now := time.Now().Unix() // timeout ist clientgesteuert -> serverseitig deckeln, damit niemand eine - // quasi-unbegrenzte Session anlegen kann. Default 1 Tag, Maximum 30 Tage. + // quasi-unbegrenzte Session anlegen kann. Default 1 Tag, Maximum 1 Jahr + // (größte Option im Login-Formular). timeoutSec, _ := strconv.ParseInt(r.FormValue("timeout"), 10, 64) - const maxTimeout = 30 * 86400 + const maxTimeout = 365 * 86400 if timeoutSec <= 0 { timeoutSec = 86400 } diff --git a/frontend/src/components/AuthBox.tsx b/frontend/src/components/AuthBox.tsx index 49c233f..a33d32e 100644 --- a/frontend/src/components/AuthBox.tsx +++ b/frontend/src/components/AuthBox.tsx @@ -53,7 +53,15 @@ export function AuthBox() {

Login

{" "} {" "} {" "} - {" "} + {" "} {" "}

Noch kein Konto? Registrieren

diff --git a/notes/api.md b/notes/api.md index e053acc..1a1e4f0 100644 --- a/notes/api.md +++ b/notes/api.md @@ -50,7 +50,7 @@ Endpunkte antworten ohne gültige Session mit `401 auth.required`. | Methode | Pfad | Auth | Request | Erfolg | |---------|------|------|---------|--------| -| POST | `/api/auth/login` | – | `user`, `pass`, `timeout` (s, Default 1 Tag, max. 30 Tage) | `200 {"status":"ok"}` + Cookie; bereits angemeldet: `200 {"status":"already_logged_in"}` | +| POST | `/api/auth/login` | – | `user`, `pass`, `timeout` (s, Default 1 Tag, max. 1 Jahr) | `200 {"status":"ok"}` + Cookie; bereits angemeldet: `200 {"status":"already_logged_in"}` | | POST | `/api/auth/newuser` | – | `user` (3–32 Zeichen), `pass1` (min. 10), `pass2` | `201 {"username"}` | | POST | `/api/auth/logout` | – | – | `200 {"status":"ok"}`, löscht Cookie | | GET | `/api/auth/sessioninfo` | ✓ | – | `200 {"uid","created_at","expires","description"}`, ohne Session `401` |