- Add sessions table to store session tokens with expiration - Create Session domain model and SessionRepository trait - Implement SqlSessionRepository for session persistence - Update is_authenticated() to validate tokens against database - Sessions expire after 30 days - Session tokens hashed with SHA-256 before storage - Delete sessions from database on logout - Update all page handlers to properly validate sessions This prevents session hijacking by ensuring only valid, unexpired tokens stored in the database can authenticate requests. Co-authored-by: jnsgruk <668505+jnsgruk@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| auth_api.rs | ||
| helpers.rs | ||
| main.rs | ||
| roasters_api.rs | ||
| roasts_api.rs | ||
| timeline.rs | ||