4 ms·
Very cool. `man login` says that you only see the username we type in. How are you authenticating?
by djacobs 15y ago
Very cool. `man login` says that you only see the username we type in. How are you authenticating?
- JonnieCache 15y agoI'm guessing it all happens client side from the browser.
- pfarrell 15y agoI don't want to "guess" that. I'd like it really spelled out. I tried "login" and got a 500 from a debian server. I wouldn't send my credentials through some random server just because it was on HN. --edit: I was wrong, it wasn't a 500 error, it was a 404. I don't want to cast too much suspicion here, just making a point about being appropriately paranoid about giving out my creds. This site could be totally cool, I want it transparent to me before I login.
- elliottcarlson 15y agoI'm assuming it's trying to load an OAuth screen - but the page is broken so won't even work to begin with.
- warmfuzzykitten 15y agologin => 404 The requested URL /_ah/conflogin was not found on this server
- djacobs 15y agoWhile the client side has some login-related logic, it looks like authentication happens server-side. From the source: goosh.module.login = function () { this.name = "login"; this.aliases = new Array("login"); this.help = "login with your google account *"; this.helptext = "goosh sees only your username"; this.parameters = ""; this.cb = function (A, B) { if (goosh.ajax.iscontext(A)) { if (B && B != "guest") { goosh.lib.cookie.set("loggedin", "1", 365) } goosh.config.user = B; if (goosh.config.user != "guest") { goosh.gui.outln("You're logged in as: " + goosh.config.user + "<br/>"); goosh.set.init(); goosh.gui.updateprompt(); goosh.gui.showinput(); goosh.gui.focusinput(); goosh.gui.scroll() } else { goosh.ajax.query("http://goosh.appspot.com/dologin?") } goosh.gui.showinput(); goosh.gui.focusinput(); goosh.gui.scroll() } }; this.call = function (A) { goosh.ajax.query("http://goosh.appspot.com/ status?callback=goosh.modobj.login.cb") } }; goosh.modules.register("login");