package handlers import ( "net/http" "github.com/gin-contrib/sessions" "github.com/gin-gonic/gin" "gorm.io/gorm" "go_blog/models" ) // LoginPage renders the login form. func LoginPage() gin.HandlerFunc { return func(c *gin.Context) { tr := getTr(c) data := DefaultData(c) data["Title"] = tr["page_login"] if c.Query("error") == "1" { data["Error"] = tr["login_error"] } c.HTML(http.StatusOK, "login", data) } } // Login processes the login form submission. func Login(db *gorm.DB) gin.HandlerFunc { return func(c *gin.Context) { username := c.PostForm("username") password := c.PostForm("password") var user models.User if err := db.Where("username = ?", username).First(&user).Error; err != nil { c.Redirect(http.StatusFound, "/login?error=1") return } if !user.CheckPassword(password) { c.Redirect(http.StatusFound, "/login?error=1") return } // Refuse login for non-normal accounts (disabled / locked / unactivated). if user.Status != models.StatusNormal { c.Redirect(http.StatusFound, "/login?error=1") return } // Create session. session := sessions.Default(c) session.Set("user_id", user.ID) session.Set("username", user.Username) if err := session.Save(); err != nil { c.String(http.StatusInternalServerError, "Failed to save session") return } // Redirect based on user role: admins to /admin, others to home if user.Role == models.RoleAdmin { c.Redirect(http.StatusFound, "/admin") } else { c.Redirect(http.StatusFound, "/") } } } // Logout clears the session and redirects home. func Logout() gin.HandlerFunc { return func(c *gin.Context) { session := sessions.Default(c) session.Clear() session.Save() c.Redirect(http.StatusFound, "/") } }