From b61400085aa907ec85a8da4d8ec37579b2d3a7b0 Mon Sep 17 00:00:00 2001 From: Andrew Stowell Date: Sat, 17 Jan 2026 10:57:57 -0500 Subject: [PATCH] frontend support for password --- config/packages/twig.yaml | 3 ++ config/services.yaml | 7 ++-- docs/env.example | 3 +- src/ConfigBag.php | 11 +----- templates/_style.html.twig | 7 +++- templates/base.html.twig | 2 +- templates/login.html.twig | 77 +++++++++++++++++++++++++++++++++----- 7 files changed, 85 insertions(+), 25 deletions(-) diff --git a/config/packages/twig.yaml b/config/packages/twig.yaml index 42ff8cd..7b5e99e 100644 --- a/config/packages/twig.yaml +++ b/config/packages/twig.yaml @@ -3,6 +3,7 @@ twig: strict_variables: true globals: env: + allow_password: '%env(STATIC_SECRET_ENABLED)%' title: '%env(TITLE)%' bg_color: '%env(BG_COLOR)%' fg_color: '%env(FG_COLOR)%' @@ -10,8 +11,10 @@ twig: return_field: '%env(QUERY_PREFIX)%return' id_field: '%env(QUERY_PREFIX)%id' token_field: '%env(QUERY_PREFIX)%token' + password_field: '%env(QUERY_PREFIX)%password' id_name: '%env(ID_NAME)%' token_name: '%env(TOKEN_NAME)%' + password_name: '%env(PASSWORD_NAME)%' submit_name: '%env(SUBMIT_NAME)%' error_message: '%env(ERROR_MESSAGE)%' teapot_title: '%env(TEAPOT_TITLE)%' diff --git a/config/services.yaml b/config/services.yaml index 90727df..fb43656 100644 --- a/config/services.yaml +++ b/config/services.yaml @@ -26,12 +26,12 @@ parameters: # --- extra variables --- # query parameter prefix to prevent collisions env(QUERY_PREFIX): '_preauth_' - # allow files in /app/public/assets directory to be served, false to disable - env(ASSETS): '1' # default enabled, boolean # how long do we allow all traffic from an ip address after successful login # could be useful if you have a system which does not handle cookies env(IP_TTL): '0' # default disabled, time in seconds # if desired, in addition to supporting a TOTP, you can set a static password + # TODO rely on checking enabled, instead of the secret directly throughout the code + env(STATIC_SECRET_ENABLED): '0' # boolean env(STATIC_SECRET): '' # default disabled # once blocked, do we respond with "I'm a teapot", false to use "Too many requests" env(TEAPOT): '1' # boolean @@ -43,6 +43,7 @@ parameters: env(ERROR_COLOR): '#ffb16d' env(ID_NAME): 'Session ID' env(TOKEN_NAME): 'Authentication Token' + env(PASSWORD_NAME): 'Authentication Password' env(SUBMIT_NAME): 'Submit' env(ERROR_MESSAGE): 'Unsuccessful login attempt' # title and message to use on block page, if teapot is true @@ -59,8 +60,8 @@ parameters: app.query_prefix: '%env(QUERY_PREFIX)%' app.totp_uri: '%env(TOTP_URI)%' - app.assets: '%env(ASSETS)%' app.ip_ttl: '%env(IP_TTL)%' + app.static_secret_enabled: '%env(STATIC_SECRET_ENABLED)%' app.static_secret: '%env(STATIC_SECRET)%' app.teapot: '%env(TEAPOT)%' diff --git a/docs/env.example b/docs/env.example index f67975c..c4b6ca2 100644 --- a/docs/env.example +++ b/docs/env.example @@ -27,7 +27,8 @@ #IP_TTL=0 # default disabled, time in seconds # if desired, in addition to supporting a TOTP, you can set a static password -#STATIC_SECRET='' # deafult disabled +#STATIC_SECRET_ENABLED='0' # boolean, disabled by default +#STATIC_SECRET='' # default disabled # once blocked, do we respond with "I'm a teapot", false to use "Too many requests" #TEAPOT=true # default enabled, boolean diff --git a/src/ConfigBag.php b/src/ConfigBag.php index 2af294d..66d022f 100644 --- a/src/ConfigBag.php +++ b/src/ConfigBag.php @@ -15,7 +15,6 @@ final readonly class ConfigBag { private int $limitTtl; private string $queryPrefix; private string $totpUri; - private ?string $assetsDir; private ?int $ipTtl; private ?string $staticSecret; private bool $teapot; @@ -33,9 +32,8 @@ final readonly class ConfigBag { #[Autowire('%app.limit_ttl%')] int $limitTtl, #[Autowire('%app.query_prefix%')] string $queryPrefix, #[Autowire('%app.totp_uri%')] string $totpUri, - #[Autowire('%app.assets%')] bool $assets, - #[Autowire('%kernel.project_dir%/public/assets/')] string $assetsDir, #[Autowire('%app.ip_ttl%')] ?int $ipTtl, + #[Autowire('%app.static_secret_enabled%')] bool $staticSecretEnabled, #[Autowire('%app.static_secret%')] ?string $staticSecret, #[Autowire('%app.teapot%')] bool $teapot, #[Autowire('%app.error_message%')] string $errorMessage, @@ -49,9 +47,8 @@ final readonly class ConfigBag { $this->limitTtl = ($limitTtl >= 1) ? $limitTtl : 86400; $this->queryPrefix = $queryPrefix; $this->totpUri = $totpUri ?: $utilities->loadTotp(); - $this->assetsDir = $assets ? $assetsDir : null; $this->ipTtl = $ipTtl ?: null; - $this->staticSecret = $staticSecret ?: null; + $this->staticSecret = $staticSecretEnabled ? ($staticSecret ?: null) : null; $this->teapot = $teapot; $this->errorMessage = $errorMessage; $this->teapotTitle = $teapotTitle; @@ -86,10 +83,6 @@ final readonly class ConfigBag { return $this->totpUri; } - public function assetsDir(): ?string { - return $this->assetsDir; - } - public function ipTtl(): ?int { return $this->ipTtl; } diff --git a/templates/_style.html.twig b/templates/_style.html.twig index d702c7a..f5048ac 100644 --- a/templates/_style.html.twig +++ b/templates/_style.html.twig @@ -5,8 +5,13 @@ html { background-color: {{ env.bg_color }}; color: {{ env.fg_color }}; display: body { display: table-cell; vertical-align: middle; } h1 { font-size: 2.5em; font-weight: normal; text-align: center; } p { color: {{ env.error_color }}; text-align: center; } -form { display: flex; flex-wrap: wrap; justify-content: center; } +form { align-items: baseline; display: flex; flex-wrap: wrap; justify-content: center; } form div { width: 45%; } div.right { text-align: right; } div.center { text-align: center; } +div.hidden { display: none; } +span { cursor: pointer; font-size: 0.75em; text-decoration: underline; } +button { background-color: #cccccc; } +input { background-color: #ffffff; max-width: 100%; } +button, input { border: 0.0625em solid #333333; border-radius: 0.25em; color: #333333; font-size: 0.9em; } diff --git a/templates/base.html.twig b/templates/base.html.twig index f17a50a..d99e1a0 100644 --- a/templates/base.html.twig +++ b/templates/base.html.twig @@ -3,7 +3,7 @@ {{ env.title }} - + {{ include('_style.html.twig') }} diff --git a/templates/login.html.twig b/templates/login.html.twig index 4b0c79f..dda8099 100644 --- a/templates/login.html.twig +++ b/templates/login.html.twig @@ -8,25 +8,82 @@
-
-
+ {% if env.allow_password %} +
+
+ 🔃 {{ env.password_name }}
+
+ + + + {% else %} +
+
+ {% endif %}