mirror of
https://github.com/GSA/notifications-admin.git
synced 2026-09-08 01:58:26 -04:00
when a user enters their 2FA code, the API will store a random UUID
against them in the database - this code is then stored on the cookie
on the front end.
At the beginning of each authenticated request, we do the following
steps:
* Retrieve the user's cookie, and get the user_id from it
* Request that user's details from the database
* populate current_user with the DB model
* run the login_required decorator, which calls
current_user.is_authenticated
is_authenticated now also checks that the database model matches the
cookie for session_id. The potential states and meanings are as follows:
database | cookie | meaning
----------+--------+---------
None | None | New user, or system just been deployed.
| | Redirect to start page.
----------+--------+---------
'abc' | None | New browser (or cleared cookies). Redirect to
| | start page.
----------+--------+---------
None | 'abc' | Invalid state (cookie is set from user obj, so
| | would only happen if DB is cleared)
----------+--------+---------
'abc' | 'abc' | Same browser. Business as usual
----------+--------+---------
'abc' | 'def' | Different browser in cookie - db has been changed
| | since then. Redirect to start
42 lines
1.1 KiB
HTML
42 lines
1.1 KiB
HTML
{% extends "withoutnav_template.html" %}
|
||
{% from "components/textbox.html" import textbox %}
|
||
{% from "components/page-footer.html" import page_footer %}
|
||
|
||
{% block per_page_title %}
|
||
Sign in
|
||
{% endblock %}
|
||
|
||
{% block maincolumn_content %}
|
||
|
||
<div class="grid-row">
|
||
<div class="column-two-thirds">
|
||
|
||
{% if again %}
|
||
<h1 class="heading-large">You need to sign in again</h1>
|
||
{% if other_device %}
|
||
<p>
|
||
We signed you out because you logged in to Notify on another device.
|
||
</p>
|
||
{% else %}
|
||
<p>
|
||
We signed you out because you haven’t used Notify for a while.
|
||
</p>
|
||
{% endif %}
|
||
{% else %}
|
||
<h1 class="heading-large">Sign in</h1>
|
||
<p>
|
||
If you do not have an account, you can
|
||
<a href="{{ url_for('.register') }}">create one now</a>.
|
||
</p>
|
||
{% endif %}
|
||
|
||
<form method="post" autocomplete="nope">
|
||
{{ textbox(form.email_address) }}
|
||
{{ textbox(form.password) }}
|
||
{{ page_footer("Continue", secondary_link=url_for('.forgot_password'), secondary_link_text="Forgot your password?") }}
|
||
</form>
|
||
</div>
|
||
</div>
|
||
|
||
{% endblock %}
|