From 9a7282ed1d43f2c866b92ecc8a593fe5d4429172 Mon Sep 17 00:00:00 2001 From: irrlicht Date: Sun, 27 Sep 2026 00:04:07 +0200 Subject: [PATCH] =?UTF-8?q?Login:=20Sitzungsdauer=20w=C3=A4hlbar=20(1=20St?= =?UTF-8?q?unde=20bis=201=20Jahr)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01TiXsPUqw7oeomZ8wZrQW5q --- auth.go | 5 +++-- frontend/src/components/AuthBox.tsx | 10 +++++++++- notes/api.md | 2 +- 3 files changed, 13 insertions(+), 4 deletions(-) diff --git a/auth.go b/auth.go index 0516759..e4bbc77 100644 --- a/auth.go +++ b/auth.go @@ -96,9 +96,10 @@ func handleLogin(w http.ResponseWriter, r *http.Request) error { func startSession(w http.ResponseWriter, r *http.Request, uid int64) error { now := time.Now().Unix() // timeout ist clientgesteuert -> serverseitig deckeln, damit niemand eine - // quasi-unbegrenzte Session anlegen kann. Default 1 Tag, Maximum 30 Tage. + // quasi-unbegrenzte Session anlegen kann. Default 1 Tag, Maximum 1 Jahr + // (größte Option im Login-Formular). timeoutSec, _ := strconv.ParseInt(r.FormValue("timeout"), 10, 64) - const maxTimeout = 30 * 86400 + const maxTimeout = 365 * 86400 if timeoutSec <= 0 { timeoutSec = 86400 } diff --git a/frontend/src/components/AuthBox.tsx b/frontend/src/components/AuthBox.tsx index 49c233f..a33d32e 100644 --- a/frontend/src/components/AuthBox.tsx +++ b/frontend/src/components/AuthBox.tsx @@ -53,7 +53,15 @@ export function AuthBox() {

Login

{" "} {" "} {" "} - {" "} + {" "} {" "}

Noch kein Konto? Registrieren

diff --git a/notes/api.md b/notes/api.md index e053acc..1a1e4f0 100644 --- a/notes/api.md +++ b/notes/api.md @@ -50,7 +50,7 @@ Endpunkte antworten ohne gültige Session mit `401 auth.required`. | Methode | Pfad | Auth | Request | Erfolg | |---------|------|------|---------|--------| -| POST | `/api/auth/login` | – | `user`, `pass`, `timeout` (s, Default 1 Tag, max. 30 Tage) | `200 {"status":"ok"}` + Cookie; bereits angemeldet: `200 {"status":"already_logged_in"}` | +| POST | `/api/auth/login` | – | `user`, `pass`, `timeout` (s, Default 1 Tag, max. 1 Jahr) | `200 {"status":"ok"}` + Cookie; bereits angemeldet: `200 {"status":"already_logged_in"}` | | POST | `/api/auth/newuser` | – | `user` (3–32 Zeichen), `pass1` (min. 10), `pass2` | `201 {"username"}` | | POST | `/api/auth/logout` | – | – | `200 {"status":"ok"}`, löscht Cookie | | GET | `/api/auth/sessioninfo` | ✓ | – | `200 {"uid","created_at","expires","description"}`, ohne Session `401` |