Files
ThothII/frontend/src/auth/LoginPage.tsx
T

162 lines
7.5 KiB
TypeScript

import { useEffect, useRef, useState } from "react";
import type { FormEvent } from "react";
import { AlertTriangle, ArrowRight, LockKeyhole } from "lucide-react";
import { ApiError } from "../api/client";
import { loginLocal } from "../api/auth";
import type { AuthenticatedUser, AuthPublicConfig } from "../api/types";
import { Button } from "../components/ui/button";
interface LoginPageProps {
config: AuthPublicConfig;
onAuthenticated: (user: AuthenticatedUser) => void;
onRetry?: () => void;
}
function loginError(error: unknown): { message: string; retry: boolean } {
if (error instanceof ApiError && error.status === 503) {
return { message: "Authentication is temporarily unavailable. Try again.", retry: true };
}
if (error instanceof ApiError && error.status === 403) {
return { message: "This sign-in request was rejected. Open ThothII from its configured address and try again.", retry: false };
}
return { message: "Invalid username or password.", retry: false };
}
export function LoginPage({ config, onAuthenticated, onRetry }: LoginPageProps) {
const localLogin = config.mode === "local" && config.localLogin;
const formRef = useRef<HTMLFormElement>(null);
const passwordRef = useRef<HTMLInputElement>(null);
const mountedRef = useRef(true);
const submittingRef = useRef(false);
const attemptRef = useRef(0);
const [submitting, setSubmitting] = useState(false);
const [error, setError] = useState<{ message: string; retry: boolean }>();
useEffect(() => {
mountedRef.current = true;
return () => { mountedRef.current = false; };
}, []);
async function submit(event: FormEvent<HTMLFormElement>) {
event.preventDefault();
if (submittingRef.current) return;
const form = event.currentTarget;
const values = new FormData(form);
const username = String(values.get("username") ?? "");
const password = String(values.get("password") ?? "");
const remember = values.get("remember") === "on";
const attempt = ++attemptRef.current;
submittingRef.current = true;
setError(undefined);
setSubmitting(true);
try {
const user = await loginLocal(username, password, remember);
if (mountedRef.current && attemptRef.current === attempt) onAuthenticated(user);
} catch (failure) {
if (mountedRef.current && attemptRef.current === attempt) setError(loginError(failure));
} finally {
submittingRef.current = false;
if (!mountedRef.current || attemptRef.current !== attempt) return;
// Passwords never enter React state and are cleared after every attempt,
// including operational failures and successful authentication.
form.reset();
setSubmitting(false);
passwordRef.current?.focus();
}
}
return (
<main className="min-h-screen bg-background px-5 py-8 text-foreground sm:px-8 sm:py-12">
<div className="mx-auto grid min-h-[calc(100vh-4rem)] max-w-5xl items-center gap-12 lg:grid-cols-[minmax(0,1fr)_26rem]">
<section className="hidden max-w-xl lg:block">
<p className="thot-label text-primary">Secure re-entry · governed workspace</p>
<h1 className="mt-4 max-w-lg font-heading text-5xl font-semibold leading-[1.03] tracking-tight sm:text-6xl">
Return to the analytical ledger.
</h1>
<p className="mt-6 max-w-md text-base leading-7 text-muted-foreground">
ThothII keeps each question, review decision, and SQL artifact inside a traceable human-in-the-loop workflow.
</p>
<div className="mt-10 flex items-center gap-3 text-sm text-muted-foreground">
<span className="h-px w-16 bg-primary" aria-hidden="true" />
<span>Access is checked before the workspace opens.</span>
</div>
</section>
<section className="mx-auto w-full max-w-md rounded-2xl border border-border/80 bg-card p-6 shadow-md sm:p-8">
<div className="mb-7">
<div className="flex items-center gap-2 text-primary" aria-hidden="true">
<LockKeyhole className="size-4" />
<span className="thot-label text-primary">ThothII access</span>
</div>
<h2 className="mt-3 font-heading text-3xl font-semibold tracking-tight">Sign in to ThothII</h2>
<p className="mt-2 text-sm leading-6 text-muted-foreground">Use your installation account to continue.</p>
</div>
{error && (
<div role="alert" aria-live="assertive" className="mb-5 grid gap-3 rounded-md border border-destructive/30 bg-destructive/5 p-3 text-sm">
<p className="flex items-start gap-2 leading-5"><AlertTriangle className="mt-0.5 size-4 shrink-0 text-destructive" />{error.message}</p>
{error.retry && onRetry && (
<Button type="button" variant="outline" size="sm" className="w-fit" onClick={onRetry}>Retry</Button>
)}
</div>
)}
{localLogin && (
<form ref={formRef} onSubmit={submit} className="grid gap-4">
<div className="grid gap-1.5">
<label htmlFor="thothii-username" className="text-sm font-semibold">Username</label>
<input
id="thothii-username"
name="username"
type="text"
autoComplete="username"
autoCapitalize="none"
spellCheck={false}
required
className="h-10 rounded-md border border-input bg-background px-3 text-sm outline-none focus-visible:ring-3 focus-visible:ring-ring/25"
/>
</div>
<div className="grid gap-1.5">
<label htmlFor="thothii-password" className="text-sm font-semibold">Password</label>
<input
ref={passwordRef}
id="thothii-password"
name="password"
type="password"
autoComplete="current-password"
required
className="h-10 rounded-md border border-input bg-background px-3 text-sm outline-none focus-visible:ring-3 focus-visible:ring-ring/25"
/>
</div>
<label className="flex items-center gap-2 text-sm text-muted-foreground">
<input name="remember" type="checkbox" className="size-4 accent-[oklch(var(--primary))]" />
<span>Remember me for 30 days</span>
</label>
<Button type="submit" size="lg" className="mt-1 w-full" disabled={submitting}>
{submitting ? "Signing in…" : "Sign in"}
{!submitting && <ArrowRight aria-hidden="true" />}
</Button>
</form>
)}
{config.oidcLogin && (
<a
href="/api/auth/oidc/login"
className="mt-4 inline-flex h-10 w-full items-center justify-center gap-2 rounded-md border border-border bg-card px-4 text-sm font-semibold shadow-xs outline-none transition-colors hover:bg-muted focus-visible:ring-3 focus-visible:ring-ring/25"
>
Continue with single sign-on
<ArrowRight aria-hidden="true" className="size-4" />
</a>
)}
{!localLogin && !config.oidcLogin && (
<p role="status" className="rounded-md border border-border bg-muted/40 p-3 text-sm text-muted-foreground">
No browser sign-in method is enabled for this installation.
</p>
)}
</section>
</div>
</main>
);
}