view mod_http_oauth2/html/login.html @ 5513:0005d4201030

mod_http_oauth2: Reject duplicate form-urlencoded parameters Per RFC 6749 section 3.1 > Request and response parameters MUST NOT be included more than once. Thanks to OAuch for pointing out Also cleans up some of the icky behavior of formdecode(), like returning a string if no '=' is included.
author Kim Alvefur <zash@zash.se>
date Fri, 02 Jun 2023 11:03:57 +0200
parents 398d936e77fb
children 46e512f4ba14
line wrap: on
line source

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1" />
<title>{site_name} - Sign in</title>
<link rel="stylesheet" href="style.css">
</head>
<body>
	<main>
	<h1>{site_name}</h1>
	<fieldset>
	<legend>Sign in</legend>
	<p>Sign in to your account to continue.</p>
	{state.error&<div class="error">
		<p>{state.error}</p>
	</div>}
	<form method="post">
		<input type="text" name="username" placeholder="Username" aria-label="Username" required {extra.no_username_hint&autofocus}{extra.username_hint& value="{extra.username_hint?}"}><br/>
		<input type="password" name="password" placeholder="Password" aria-label="Password" autocomplete="current-password" required {extra.username_hint&autofocus}><br/>
		<input type="submit" value="Sign in">
	</form>
	</fieldset>
	</main>
</body>
</html>