Provides authentication facilities for web services.
  • Common Lisp 100%
Find a file
Marcus Kammer 222774d6cd
test(auth): add comprehensive unit tests for auth-db, auth, and login
Expand the FiveAM suite from one test to 49 checks, organized into
:auth-db-tests, :auth-tests, and :login-tests sub-suites.

Coverage added for:
- auth-db: hash-password, check-password-p, add-user, authenticate-user,
  find-user, remove-user, user-exists-p, and user-exists-error
- auth: generate-csrftoken, constant-time-string=, make-auth, empty-db-p,
  auth-form-p (valid, invalid password, invalid CSRF, type error)
- login: determine-login-state, build-auth-from-request,
  generate-login-response normal-login callback

To make build-auth-from-request testable without a live HTTP request, add
*post-parameter-function* dynamic variable in src/login.lisp that defaults to
#'hunchentoot:post-parameter.
2026-08-18 10:55:28 +02:00
src test(auth): add comprehensive unit tests for auth-db, auth, and login 2026-08-18 10:55:28 +02:00
tests test(auth): add comprehensive unit tests for auth-db, auth, and login 2026-08-18 10:55:28 +02:00
.gitignore Initial commit 2025-08-14 08:47:25 +02:00
dev.metalisp.webauth.asd fix(auth-db): hash passwords with utf-8 encoding 2026-08-17 22:51:14 +02:00
LICENSE Update license to LGPL-3.0-only 2025-10-01 09:16:05 +02:00
README.org fix(auth)!: close authentication bypass in define-authentication 2026-08-17 22:49:19 +02:00

dev.metalisp.webauth

Provides authentication facilities for web services.

Example usage

  (define-survey-handler (login-handler :uri "/" :redirect-url "login" :public t) (fail created-admin logout)
    (:get (generate-login-response (determine-login-state)
                                   #'login-form
                                   "/dashboard"
                                   :fail fail
                                   :created-admin created-admin
                                   :logout logout))
    (:post (process-login-submission (determine-login-state)
                                     (build-auth-from-request))))