Changeset c80e78b in Klonkt for src/views/pages/welcome.ejs


Ignore:
Timestamp:
06/14/2026 04:39:57 AM (3 months ago)
Author:
roboburr <roboburr@…>
Branches:
main
Children:
ae924a2
Parents:
89d6536
Message:

auth: replace username/password with Google login

Listeners (and the owner) now log in via Google instead of a local
username/password account. This lowers the barrier to commenting and
removes the home-built password/registration system.

  • src/config/google.js: raw OAuth2 helpers (authorize/token/userinfo) via the built-in fetch, config-driven. Boot keeps working without credentials.
  • src/routes/auth.js: /auth/google + /auth/google/callback (find-or-create user on email, ADMIN_EMAIL -> god, set session). login/register/reset POST handlers removed; /login now shows the Google button.
  • database.js: idempotent column users.google_sub.
  • account.js + account.ejs: change-password removed.
  • auth-login.ejs / welcome.ejs: Google button instead of password form.
  • shared-styles.ejs: .btn-google styling.
  • .env.example: GOOGLE_CLIENT_ID/SECRET/REDIRECT_URI + ADMIN_EMAIL.

Existing users are matched on email (owner retains their site).
DO NOT deploy to roboburr until the Google credentials are in .env, otherwise
the owner locks themselves out.

Co-Authored-By: Claude <noreply@…>

File:
1 edited

Legend:

Unmodified
Added
Removed
  • src/views/pages/welcome.ejs

    r89d6536 rc80e78b  
    55  <% if (!user) { %>
    66    <div class="welcome-actions">
    7       <a href="/auth/register" class="btn btn-primary">Create your account</a>
    8       <a href="/auth/login" class="btn">Already have one? Login</a>
     7      <a href="/auth/login" class="btn btn-primary">Inloggen met Google</a>
    98    </div>
    10     <p class="welcome-note">The first user becomes <strong>god</strong> and gets a personal site auto-created.</p>
     9    <p class="welcome-note">De eerste gebruiker die inlogt wordt <strong>god</strong> en krijgt automatisch een eigen site.</p>
    1110  <% } else { %>
    1211    <p>Hi <%= user.username %>! No site is configured yet.</p>
Note: See TracChangeset for help on using the changeset viewer.