- Add tower and tower-cookies dependencies for session management - Create login page template with username/password form - Implement /login and /logout routes with cookie-based sessions - Update navigation bar to show Login/Logout based on auth state - Add is_authenticated field to all page templates - Hide create/update/delete UI controls when unauthenticated - Session tokens stored in secure HttpOnly cookies with SameSite=Lax - Password verification uses constant-time comparison via Argon2 Co-authored-by: jnsgruk <668505+jnsgruk@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| partials | ||
| base.html | ||
| favicon.ico | ||
| login.html | ||
| nav.html | ||
| roast_detail.html | ||
| roaster_detail.html | ||
| roasters.html | ||
| roasts.html | ||
| styles.css | ||
| timeline.html | ||