File

mod_http_oauth2/html/login.html @ 5447:aa4828f040c5

mod_http_oauth2: Enforce client scope restrictions in authorization When registering a client, a scope field can be included as a promise to only ever use those. Here we enforce that promise, if given, ensuring a client can't request or be granted a scope it didn't provide in its registration. While currently there is no restrictions at registration time, this could be changed in the future in various ways.
author Kim Alvefur <zash@zash.se>
date Thu, 11 May 2023 19:33:44 +0200
parent 5272:acab61ba7f02
child 5466:398d936e77fb
line wrap: on
line source

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1" />
<title>{site_name} - Sign in</title>
<link rel="stylesheet" href="style.css">
</head>
<body>
	<main>
	<h1>{site_name}</h1>
	<fieldset>
	<legend>Sign in</legend>
	<p>Sign in to your account to continue.</p>
	{state.error&<div class="error">
		<p>{state.error}</p>
	</div>}
	<form method="post">
		<input type="text" name="username" placeholder="Username" aria-label="Username" required autofocus><br/>
		<input type="password" name="password" placeholder="Password" aria-label="Password" autocomplete="current-password" required><br/>
		<input type="submit" value="Sign in">
	</form>
	</fieldset>
	</main>
</body>
</html>