vienalatina/apps/board/templates/logged_out.html
Claude 0c4a98b0e0
Stop offering a logout button that was never a logout
"Cerrar sesión del todo" linked straight to /user/logout on the account
server. That route is POST-only — verified in Gitea 1.22's router, which
registers m.Post("/logout", auth.SignOut) and no GET at all — so the
click was a GET, the answer was 404, and the session it promised to end
carried on untouched. It shipped in 724dada, in the commit whose message
was about not overstating what Salir does.

It cannot be repaired by turning the link into a form: the POST needs a
CSRF token belonging to that other domain, unreadable from here by
design. So the page stops pretending and gives the instruction — go
there, open the profile menu, choose Cerrar sesión — which is what the
small print underneath already said.

server-setup.md contained the whole answer and contradicted itself: one
paragraph states the logout is POST-only "so a link cannot trigger it",
and two paragraphs later promises "the link that finishes the job". The
code followed the wrong half.

Worse, a test asserted "/user/logout" in page, so the suite was
enforcing the defect rather than catching it. That assertion is now
inverted, and a template guard fails the build if any template links
there again.

199 tests.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NizVpJ2dwzCbjCrTLCjeHn
2026-09-28 15:43:32 +00:00

39 lines
1.5 KiB
HTML

{# Shown instead of bouncing back to the login page, because bouncing back would
hide the fact that one click gets you straight in again. #}
{% extends "base.html" %}
{% block title %}Sesión cerrada{% endblock %}
{% block main %}
<article class="card card--center">
<h1>Saliste del área de la comunidad</h1>
<p class="muted">
Tu sesión aquí está cerrada. Pero este navegador <strong>sigue conectado al
servidor de cuentas</strong>, que es donde se guardan las contraseñas — así
que quien use este ordenador después podría volver a entrar sin escribirla.
</p>
{# There was a "Cerrar sesión del todo" button here that linked straight to
/user/logout. It never worked: that route is POST-only, so the click was
a GET and the account server answered 404 with the session untouched.
It cannot be made to work from here either — signing out needs a CSRF
token belonging to that other domain, which this page has no way to read,
and that restriction is the whole point of the check. So the page gives
the instruction instead of pretending to do it. #}
<p>
<a class="btn" href="{{ gitea_url }}">Ir al servidor de cuentas</a>
</p>
<p class="muted small">
Allí, abre el menú de tu perfil (arriba a la derecha) y elige
<em>Cerrar sesión</em>. Cerrar el navegador del todo también sirve.
</p>
<p class="muted small">
En tu propio ordenador no hace falta: puedes volver a entrar cuando quieras.
</p>
<p><a class="linkish" href="{{ url_for('auth.login') }}">Volver a entrar</a></p>
</article>
{% endblock %}