T10.6 D13 - strip the password UI; "Forgot password?" goes to Okta
login.html/login.js: the two reset views are gone along with the reset-token handling, and the sign-in form now says which password to type - "your Windows password, the same one you use to sign in to your computer" - using the .hint class the page already had, so no new CSS and no new literal. "Forgot password?" is KEPT and points at https://primecontrols.okta.com/. An earlier draft of this task deleted the link and I proposed a plain "contact IT" sentence instead; Okta is the better answer, and with no app password and no break-glass it is the only recovery path that exists. Three details that would each have broken it: - The old click handler on #forgot-link called preventDefault() to swap views. Left in place it would have silently swallowed the navigation, so the link would look right and do nothing. There is now deliberately no handler, and login.js says why so nobody adds one back. - target="_blank" without rel="noopener noreferrer" hands the opened page a window.opener handle back to the login page. - Worth recording since it was checked rather than assumed: the CSP allows this. form-action 'self' governs form submission, not link navigation, and no navigate-to directive is set - so a plain <a href> off-origin is fine and the nginx config needs no change. login.js also handles 503 distinctly now. T10.2 made that mean "the directory is unreachable or misconfigured", which is our fault - showing "invalid password" would send people hunting for a password they no longer have while a deploy is broken. Also removed, because T10.3 deleted the endpoints behind them and leaving them would have produced visible 404s rather than dead-but-harmless markup: auth-guard.js the whole change-password dialog (POST /api/auth/password) wp-sidenav.js the "Password / Change your password" menu entry that opened it users.js the per-row "Reset password" action users.js the password field in the create-account form - NewUserIn no users.html longer accepts one, so the form was posting a rejected field The self-row placeholder button pointed at a top-bar Password link that no longer exists; it is now a plain "you" marker. Verified: node --check passes on all four touched JS files; the only password references left in html/ are the sign-in form and the SMTP config in admin.js, which is unrelated and stays. Logged BL-027 rather than acted on: the Okta URL is the first sign of an Okta tenant on this estate, which means an OIDC flow is available in principle and would remove the domain-lockout hazard that forced AUTH_MAX_ATTEMPTS to 2. D13 was decided and reaffirmed and T10.1-T10.4 are built, so swapping the mechanism mid-wave is the reordering CLAUDE.md forbids. Recording is not reopening. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
149
html/login.js
149
html/login.js
@@ -1,26 +1,20 @@
|
||||
/* Login page logic for the Work Package Suite.
|
||||
|
||||
Three views on one page:
|
||||
• sign in posts to /api/auth/login. On success the server sets an
|
||||
HttpOnly session cookie (not readable here — that's the
|
||||
point) and we redirect to ?next= or the home page.
|
||||
• forgot password posts to /api/auth/forgot-password, which emails a
|
||||
single-use link. Only offered when the server reports
|
||||
email is actually configured (/api/auth/reset-available);
|
||||
otherwise we say to ask an admin.
|
||||
• set a new password shown when the page is opened as login.html?reset=<token>
|
||||
from that email. Posts to /api/auth/reset-password.
|
||||
One view. Sign in posts to /api/auth/login, the server authenticates by binding
|
||||
to the domain over LDAPS (D13), and on success sets an HttpOnly session cookie —
|
||||
not readable from here, which is the point — after which we redirect to ?next=
|
||||
or the home page. The password entered is the person's WINDOWS password.
|
||||
|
||||
The reset token stays in the URL only until it's used; on success we strip it
|
||||
from the address bar so it isn't left in history or copied out of the bar. */
|
||||
There is no forgot-password flow and no reset view: the suite holds no password
|
||||
to reset. "Forgot password?" is a plain external link to Okta in login.html, so
|
||||
there is deliberately no click handler for it here — one that called
|
||||
preventDefault() would swallow the navigation. */
|
||||
(function () {
|
||||
'use strict';
|
||||
|
||||
var errorBox = document.getElementById('error');
|
||||
var okBox = document.getElementById('ok');
|
||||
|
||||
function show(el) { if (el) el.style.display = ''; }
|
||||
function hide(el) { if (el) el.style.display = 'none'; }
|
||||
function byId(id) { return document.getElementById(id); }
|
||||
|
||||
function showError(msg) {
|
||||
@@ -28,11 +22,6 @@
|
||||
errorBox.textContent = msg;
|
||||
errorBox.classList.add('show');
|
||||
}
|
||||
function showOk(msg) {
|
||||
errorBox.classList.remove('show');
|
||||
okBox.textContent = msg;
|
||||
okBox.classList.add('show');
|
||||
}
|
||||
function clearBanners() {
|
||||
errorBox.classList.remove('show');
|
||||
okBox.classList.remove('show');
|
||||
@@ -49,10 +38,6 @@
|
||||
return 'index.html';
|
||||
}
|
||||
|
||||
function resetToken() {
|
||||
try { return new URLSearchParams(location.search).get('reset') || ''; } catch (e) { return ''; }
|
||||
}
|
||||
|
||||
function postJson(url, payload) {
|
||||
return fetch(url, {
|
||||
method: 'POST',
|
||||
@@ -70,18 +55,11 @@
|
||||
return (typeof d === 'string' && d) ? d : fallback;
|
||||
}
|
||||
|
||||
function view(which) {
|
||||
clearBanners();
|
||||
['login', 'forgot', 'reset'].forEach(function (v) {
|
||||
(which === v ? show : hide)(byId('view-' + v));
|
||||
});
|
||||
}
|
||||
|
||||
// ── sign in ────────────────────────────────────────────────────────────────
|
||||
var form = byId('login-form');
|
||||
var submitBtn = byId('submit');
|
||||
// Guarded because a cached older login.html may not have the reset views; an
|
||||
// unguarded addEventListener on null would break sign-in itself.
|
||||
// Guarded: an unguarded addEventListener on null would break sign-in itself if a
|
||||
// cached older login.html were served.
|
||||
if (!form || !submitBtn) return;
|
||||
form.addEventListener('submit', function (e) {
|
||||
e.preventDefault();
|
||||
@@ -98,6 +76,10 @@
|
||||
if (res.status === 401) showError('Invalid username or password.');
|
||||
else if (res.status === 403) showError(detail(res, 'Your account is disabled.'));
|
||||
else if (res.status === 429) showError(detail(res, 'Too many failed attempts. Try again later.'));
|
||||
// 503 means the directory is unreachable or misconfigured — OUR fault, not a
|
||||
// wrong password. Saying so stops people hunting for a password they no
|
||||
// longer have while a deploy is broken.
|
||||
else if (res.status === 503) showError(detail(res, 'Sign-in is temporarily unavailable. Contact IT.'));
|
||||
else showError(detail(res, 'Sign-in failed (HTTP ' + res.status + ').'));
|
||||
submitBtn.disabled = false;
|
||||
submitBtn.textContent = 'Sign in';
|
||||
@@ -109,107 +91,4 @@
|
||||
});
|
||||
});
|
||||
|
||||
// ── forgot password ────────────────────────────────────────────────────────
|
||||
var resetAvailable = null; // null = not checked yet
|
||||
|
||||
function checkResetAvailable() {
|
||||
if (resetAvailable !== null) return Promise.resolve(resetAvailable);
|
||||
return fetch('/api/auth/reset-available')
|
||||
.then(function (r) { return r.ok ? r.json() : null; })
|
||||
.then(function (j) { resetAvailable = !!(j && j.enabled); return resetAvailable; })
|
||||
.catch(function () { resetAvailable = false; return false; });
|
||||
}
|
||||
|
||||
(byId('forgot-link') || {addEventListener: function(){}}).addEventListener('click', function (e) {
|
||||
e.preventDefault();
|
||||
view('forgot');
|
||||
// Prefill from the sign-in box so nobody types their username twice.
|
||||
var u = byId('username').value.trim();
|
||||
if (u) byId('forgot-username').value = u;
|
||||
checkResetAvailable().then(function (enabled) {
|
||||
// With email off there's nothing to submit — say so and hide the form.
|
||||
(enabled ? hide : show)(byId('forgot-unavailable'));
|
||||
(enabled ? show : hide)(byId('forgot-form'));
|
||||
if (enabled) byId('forgot-username').focus();
|
||||
});
|
||||
});
|
||||
|
||||
(byId('back-to-login') || {addEventListener: function(){}}).addEventListener('click', function (e) {
|
||||
e.preventDefault();
|
||||
view('login');
|
||||
});
|
||||
|
||||
var forgotForm = byId('forgot-form') || document.createElement('form');
|
||||
var forgotBtn = byId('forgot-submit') || document.createElement('button');
|
||||
forgotForm.addEventListener('submit', function (e) {
|
||||
e.preventDefault();
|
||||
clearBanners();
|
||||
var who = byId('forgot-username').value.trim();
|
||||
if (!who) { showError('Enter your username or email.'); return; }
|
||||
forgotBtn.disabled = true;
|
||||
forgotBtn.textContent = 'Sending…';
|
||||
postJson('/api/auth/forgot-password', { username: who })
|
||||
.then(function (res) {
|
||||
if (res.status === 503) {
|
||||
showError(detail(res, "Password reset by email isn't available. Ask an administrator."));
|
||||
} else if (res.ok) {
|
||||
// Deliberately the same message whether or not the account exists.
|
||||
showOk('If that account exists, a reset link is on its way. The link expires in an hour.');
|
||||
hide(forgotForm);
|
||||
} else {
|
||||
showError(detail(res, 'Could not send the reset email (HTTP ' + res.status + ').'));
|
||||
}
|
||||
forgotBtn.disabled = false;
|
||||
forgotBtn.textContent = 'Email me a reset link';
|
||||
})
|
||||
.catch(function () {
|
||||
showError('Could not reach the server. Check your connection and try again.');
|
||||
forgotBtn.disabled = false;
|
||||
forgotBtn.textContent = 'Email me a reset link';
|
||||
});
|
||||
});
|
||||
|
||||
// ── set a new password (from the emailed link) ──────────────────────────────
|
||||
(byId('reset-to-login') || {addEventListener: function(){}}).addEventListener('click', function (e) {
|
||||
e.preventDefault();
|
||||
view('login');
|
||||
});
|
||||
|
||||
var resetForm = byId('reset-form') || document.createElement('form');
|
||||
var resetBtn = byId('reset-submit') || document.createElement('button');
|
||||
resetForm.addEventListener('submit', function (e) {
|
||||
e.preventDefault();
|
||||
clearBanners();
|
||||
var token = resetToken();
|
||||
var pw = byId('new-password').value;
|
||||
var pw2 = byId('new-password2').value;
|
||||
if (!token) { showError('This reset link is incomplete. Request a new one.'); return; }
|
||||
if (pw !== pw2) { showError('The two passwords do not match.'); return; }
|
||||
if (pw.length < 12) { showError('Password must be at least 12 characters.'); return; }
|
||||
|
||||
resetBtn.disabled = true;
|
||||
resetBtn.textContent = 'Saving…';
|
||||
postJson('/api/auth/reset-password', { token: token, new_password: pw })
|
||||
.then(function (res) {
|
||||
if (res.ok) {
|
||||
// Take the token out of the URL before anything else — it's spent.
|
||||
try { history.replaceState(null, '', 'login.html'); } catch (err) {}
|
||||
view('login');
|
||||
showOk('Password updated. Sign in with your new password.');
|
||||
byId('username').focus();
|
||||
return;
|
||||
}
|
||||
showError(detail(res, 'Could not set your password (HTTP ' + res.status + ').'));
|
||||
resetBtn.disabled = false;
|
||||
resetBtn.textContent = 'Set password & sign in';
|
||||
})
|
||||
.catch(function () {
|
||||
showError('Could not reach the server. Check your connection and try again.');
|
||||
resetBtn.disabled = false;
|
||||
resetBtn.textContent = 'Set password & sign in';
|
||||
});
|
||||
});
|
||||
|
||||
// Arriving from the reset email opens straight into the new-password view.
|
||||
if (resetToken()) view('reset');
|
||||
})();
|
||||
|
||||
Reference in New Issue
Block a user