Sign-in
How the placeholder sign-in works, what it does not protect, and how to connect it to your own API.
How it works
- The sign-in page at
/en/loginchecks the email and password against one account, in the browser. The sign-in details are in the installation guide. - After a successful sign-in the browser keeps the user, so a reload stays signed in. Logout in the user menu, or Sign Out in the settings, forgets it. The header and the profile in the settings show the signed-in user.
- Every page under
/dashboardchecks for that user in the browser and sends anyone else to the sign-in page. - The form checks the fields first: a valid email, and a password of at least 6 characters.
- The Apple and Google buttons, Remember me and Forgot password? are in place for your own sign-in and do nothing yet.
What it does not protect
The placeholder sign-in is not security. The account is in the code that every visitor's browser downloads, and the pages are hidden in the browser, not on a server. Before real users or real data reach the dashboard, connect it to your own API and check the session on your server.
The template includes the code to change for this, with a worked example for buyers.
Where the sign-in lives
Included with your purchase. Sign in to read, or open it in your download.
The files behind the account, the session, the page guard and the social buttons.
Connect it to your API
Included with your purchase. Sign in to read, or open it in your download.
A worked example that signs in, restores and ends the session through your own API.
Check the session on the server
Included with your purchase. Sign in to read, or open it in your download.
How to turn signed-out visitors away in src/proxy.ts, before any dashboard page loads.
The Apple and Google buttons
Included with your purchase. Sign in to read, or open it in your download.
Where the social sign-in buttons are defined and wired.