b882c304b1
Admin login & user management (novaconium/ISSUES.md): session-based
login against a SQLite users table replaces the single-user HTTP Basic
Auth stopgap (admin_username/admin_password_hash and /admin/password-hash
are gone; one admin_auth_enabled flag, off by default with zero DB
footprint). New /admin/login, /admin/logout (POST-only, real page), and
/admin/users pages plus bin/create-admin-user.php.
First user created is the admin; everyone after is registered with a
unique normalized email and an optional group. /admin/* and drafts are
admin-only; Lib\Access gates page content from sidecars
(Access::require('group:members')) with login-redirect/404 responses —
public by default, static pages always public by construction. User
management covers disable/enable, delete, promote/demote, group, email,
and password, with last-active-admin lockout guards.
Also: Session::regenerate() against fixation, friendly missing-PDO-driver
errors in Lib\Db, docs at /admin/docs/access-control and updates across
admin-auth/drafts/sidecars/config/libraries and README/AGENTS.md.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
24 lines
828 B
Twig
24 lines
828 B
Twig
{% extends layout %}
|
|
|
|
{% import '_layout/icons.twig' as icons %}
|
|
|
|
{% block title %}Log out{% endblock %}
|
|
|
|
{% block description %}Log out of the admin area.{% endblock %}
|
|
|
|
{% block robots %}noindex, nofollow{% endblock %}
|
|
|
|
{% block content %}
|
|
<article>
|
|
<h1 class="icon-heading">{{ icons.external_link() }}Log out</h1>
|
|
<p>Ends your admin session on the server — you'll need to log in again at <a href="/admin/login">/admin/login</a> to get back in.</p>
|
|
{% if securityError %}
|
|
<p><strong>Your session expired before submitting — please try again.</strong></p>
|
|
{% endif %}
|
|
<form method="post">
|
|
<input type="hidden" name="{{ csrfField }}" value="{{ csrfToken }}">
|
|
<button type="submit">Log out</button>
|
|
</form>
|
|
</article>
|
|
{% endblock %}
|