File

mod_http_oauth2/html/login.html @ 5407:149634647b48

mod_http_oauth2: Don't issue client_secret when not using authentication This is pretty much only for implicit flow, which is considered insecure anyway, so this is of limited value. If we delete all the implicit flow code, this could be reverted.
author Kim Alvefur <zash@zash.se>
date Tue, 02 May 2023 16:39:32 +0200
parent 5272:acab61ba7f02
child 5466:398d936e77fb
line wrap: on
line source

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1" />
<title>{site_name} - Sign in</title>
<link rel="stylesheet" href="style.css">
</head>
<body>
	<main>
	<h1>{site_name}</h1>
	<fieldset>
	<legend>Sign in</legend>
	<p>Sign in to your account to continue.</p>
	{state.error&<div class="error">
		<p>{state.error}</p>
	</div>}
	<form method="post">
		<input type="text" name="username" placeholder="Username" aria-label="Username" required autofocus><br/>
		<input type="password" name="password" placeholder="Password" aria-label="Password" autocomplete="current-password" required><br/>
		<input type="submit" value="Sign in">
	</form>
	</fieldset>
	</main>
</body>
</html>