Files
Mirror-Proxy/web/static/login.html
T
AgentandHAPI bea74a6316
Build and Push to GHCR / build-and-push (push) Has been cancelled
feat: add admin login page with session auth
Replace HTTP Basic Auth with a dedicated login page using
cookie-based session authentication.

- Add web/static/login.html with form-based login UI
- Add in-memory session store with configurable timeout
- Add /api/auth/login, /api/auth/logout, /api/auth/me endpoints
- Replace BasicAuth middleware with SessionAuth
- Add session_timeout config field (default 24h)
- Remove listen_addr from settings UI

via [HAPI](https://hapi.run)

Co-Authored-By: HAPI <[email protected]>
2026-05-24 16:43:06 +08:00

165 lines
5.2 KiB
HTML

<!DOCTYPE html>
<html lang="zh-CN">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>登录 - Mirror Proxy</title>
<style>
* { margin: 0; padding: 0; box-sizing: border-box; }
body {
font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, sans-serif;
background: linear-gradient(135deg, #1a1a2e 0%, #16213e 100%);
min-height: 100vh;
display: flex;
align-items: center;
justify-content: center;
}
.login-card {
background: white;
border-radius: 12px;
padding: 40px;
width: 90%;
max-width: 400px;
box-shadow: 0 10px 40px rgba(0,0,0,0.3);
}
.login-card h1 {
font-size: 24px;
color: #1a1a2e;
margin-bottom: 8px;
text-align: center;
}
.login-card .subtitle {
text-align: center;
color: #888;
font-size: 14px;
margin-bottom: 30px;
}
.form-group {
margin-bottom: 18px;
}
.form-group label {
display: block;
margin-bottom: 6px;
font-size: 14px;
font-weight: 500;
color: #444;
}
.form-group input {
width: 100%;
padding: 12px 14px;
border: 1px solid #ddd;
border-radius: 6px;
font-size: 15px;
transition: border-color 0.2s;
}
.form-group input:focus {
outline: none;
border-color: #007bff;
}
.btn {
width: 100%;
padding: 12px;
border: none;
border-radius: 6px;
font-size: 15px;
font-weight: 500;
cursor: pointer;
transition: all 0.2s;
}
.btn-primary {
background: #007bff;
color: white;
}
.btn-primary:hover { background: #0056b3; }
.btn-primary:active { transform: scale(0.98); }
.btn:disabled {
background: #6c757d;
cursor: not-allowed;
}
.error {
background: #f8d7da;
color: #721c24;
padding: 10px 14px;
border-radius: 6px;
font-size: 13px;
margin-bottom: 18px;
display: none;
}
.error.active { display: block; }
</style>
</head>
<body>
<div class="login-card">
<h1>Mirror Proxy</h1>
<p class="subtitle">管理后台登录</p>
<div class="error" id="errorMsg"></div>
<div class="form-group">
<label>用户名</label>
<input type="text" id="username" placeholder="请输入用户名" autocomplete="username" autofocus>
</div>
<div class="form-group">
<label>密码</label>
<input type="password" id="password" placeholder="请输入密码" autocomplete="current-password">
</div>
<button class="btn btn-primary" id="loginBtn" onclick="doLogin()">登录</button>
</div>
<script>
async function checkAuth() {
try {
const res = await fetch('/api/auth/me', { credentials: 'same-origin' });
if (res.ok) {
window.location.href = '../';
}
} catch (e) {}
}
checkAuth();
async function doLogin() {
const username = document.getElementById('username').value.trim();
const password = document.getElementById('password').value;
const errorEl = document.getElementById('errorMsg');
const btn = document.getElementById('loginBtn');
if (!username || !password) {
errorEl.textContent = '请输入用户名和密码';
errorEl.classList.add('active');
return;
}
btn.textContent = '登录中...';
btn.disabled = true;
try {
const res = await fetch('/api/auth/login', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ username, password })
});
if (res.ok) {
window.location.href = '../';
} else {
const data = await res.json().catch(() => ({}));
errorEl.textContent = data.error || '用户名或密码错误';
errorEl.classList.add('active');
}
} catch (e) {
errorEl.textContent = '登录失败: ' + e.message;
errorEl.classList.add('active');
} finally {
btn.textContent = '登录';
btn.disabled = false;
}
}
document.getElementById('password').addEventListener('keydown', (e) => {
if (e.key === 'Enter') doLogin();
});
document.getElementById('username').addEventListener('keydown', (e) => {
if (e.key === 'Enter') document.getElementById('password').focus();
});
</script>
</body>
</html>