Coverage for gws-app/gws/plugin/auth_method/web/__init__.py: 100%

0 statements  

« prev     ^ index     » next       coverage.py v7.16.2, created at 2026-10-05 13:35 +0200

1"""Web authentication method. 

2 

3Users log in with a login form in the client. On success, the method creates a 

4session in the session manager and sends its uid to the browser in an 

5``HttpOnly`` session cookie. On every request, the session is looked up by the 

6cookie. If the cookie refers to an unknown or expired session, the request gets 

7a placeholder "deleted" session for the guest user, and the cookie is removed 

8at the end of the request. For other sessions, the cookie is set and the 

9session is touched at the end of the request, if the response status is below 

10400. 

11 

12If the authenticated user has an ``mfaUid``, the login needs a second step: the 

13method starts a transaction with the multi-factor adapter of that uid and keeps 

14it in a guest session until the user has entered a valid code. 

15 

16If ``secure`` is set (the default), logins are only accepted over HTTPS and the 

17cookie is marked ``Secure``. 

18 

19Submodules 

20---------- 

21 

22- ``core`` - the ``web`` authentication method: session cookies, login, 

23 logout, multi-factor verification and restart, and the redirect of denied 

24 page requests to a login page (``loginRedirect``). Also the request and 

25 response types of the login API. 

26- ``action`` - the ``auth`` action, the client API of the method: 

27 ``authCheck``, ``authLogin``, ``authLogout``, ``authMfaVerify`` and 

28 ``authMfaRestart``. The action requires a configured ``web`` method. 

29- ``js`` - the client part. 

30 

31With ``loginRedirect``, denied GET requests (status ``401`` or ``403``) whose 

32URI matches ``pattern`` are redirected to ``target``. The original URI is 

33passed in the ``to`` parameter; the client can send it back with the login 

34request to return there after the login. 

35 

36Example:: 

37 

38 auth.methods+ { 

39 type "web" 

40 cookieName "auth" 

41 loginRedirect { 

42 pattern "^/(demo|project)" 

43 target "/login" 

44 } 

45 } 

46 

47 actions+ { 

48 type "auth" 

49 permissions.read "allow all" 

50 } 

51"""