feat: base UI shell with themes, auth pages, profile, and role navigation (phase 4)
- embedded Go templates + vanilla ES-module JS + hand-written CSS, no build step
- exact §10 beige light / dark design tokens, square edges (radius 2px),
system font stack, visible focus rings
- theme toggle persisted to localStorage and the user profile
- login/register/change-password pages wired to the auth API
- profile page: avatar upload (image-sniffed, old file cleanup), bio,
contacts, arbitrary extra key/value fields, optimistic-concurrency 409
- role-based top navigation with placeholders for later-phase areas
- GET /files/{id} with scope-based access (session) or signed token (§5.1)
- security headers incl. CSP without unsafe-inline scripts
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
import { api } from '/static/js/api.js';
|
||||
|
||||
const form = document.getElementById('login-form');
|
||||
const errorBox = document.getElementById('error');
|
||||
|
||||
function safeNext() {
|
||||
const next = new URLSearchParams(window.location.search).get('next') || '/';
|
||||
return next.startsWith('/') && !next.startsWith('//') ? next : '/';
|
||||
}
|
||||
|
||||
form.addEventListener('submit', async (e) => {
|
||||
e.preventDefault();
|
||||
errorBox.textContent = '';
|
||||
try {
|
||||
const res = await api('POST', '/api/v1/auth/login', {
|
||||
email: document.getElementById('email').value.trim(),
|
||||
password: document.getElementById('password').value,
|
||||
});
|
||||
window.location.href = res.mustChangePassword ? '/change-password' : safeNext();
|
||||
} catch (err) {
|
||||
errorBox.textContent = err.message;
|
||||
}
|
||||
});
|
||||
Reference in New Issue
Block a user