Coverage for gws-app/gws/plugin/auth_method/web/__init__.py: 100%
0 statements
« prev ^ index » next coverage.py v7.16.2, created at 2026-10-05 13:35 +0200
« prev ^ index » next coverage.py v7.16.2, created at 2026-10-05 13:35 +0200
1"""Web authentication method.
3Users log in with a login form in the client. On success, the method creates a
4session in the session manager and sends its uid to the browser in an
5``HttpOnly`` session cookie. On every request, the session is looked up by the
6cookie. If the cookie refers to an unknown or expired session, the request gets
7a placeholder "deleted" session for the guest user, and the cookie is removed
8at the end of the request. For other sessions, the cookie is set and the
9session is touched at the end of the request, if the response status is below
10400.
12If the authenticated user has an ``mfaUid``, the login needs a second step: the
13method starts a transaction with the multi-factor adapter of that uid and keeps
14it in a guest session until the user has entered a valid code.
16If ``secure`` is set (the default), logins are only accepted over HTTPS and the
17cookie is marked ``Secure``.
19Submodules
20----------
22- ``core`` - the ``web`` authentication method: session cookies, login,
23 logout, multi-factor verification and restart, and the redirect of denied
24 page requests to a login page (``loginRedirect``). Also the request and
25 response types of the login API.
26- ``action`` - the ``auth`` action, the client API of the method:
27 ``authCheck``, ``authLogin``, ``authLogout``, ``authMfaVerify`` and
28 ``authMfaRestart``. The action requires a configured ``web`` method.
29- ``js`` - the client part.
31With ``loginRedirect``, denied GET requests (status ``401`` or ``403``) whose
32URI matches ``pattern`` are redirected to ``target``. The original URI is
33passed in the ``to`` parameter; the client can send it back with the login
34request to return there after the login.
36Example::
38 auth.methods+ {
39 type "web"
40 cookieName "auth"
41 loginRedirect {
42 pattern "^/(demo|project)"
43 target "/login"
44 }
45 }
47 actions+ {
48 type "auth"
49 permissions.read "allow all"
50 }
51"""