Files
aigen/server/api/auth/login.post.ts
T
TowstyandCursor bc0ea613c1 Add a password-gated private instance mode for xaigen.
Keep Authentik on aigen, isolate library data per instance, and purge Comfy outputs from the desktop after they are saved on the server.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-25 19:24:00 -05:00

18 lines
746 B
TypeScript

export default defineEventHandler(async (event) => {
if (!passwordAuthEnabled()) {
throw createError({ statusCode: 404, statusMessage: 'Password login is not enabled' })
}
assertLoginAllowed(event)
const body = await readBody<{ username?: string; password?: string }>(event)
const username = String(body?.username || '')
const password = String(body?.password || '')
const matched = await verifyLocalLogin(username, password)
if (!matched) {
recordLoginFailure(event)
throw createError({ statusCode: 401, statusMessage: 'Incorrect username or password' })
}
clearLoginFailures(event)
setSessionUser(event, { sub: `local:${privateInstanceId()}`, name: matched })
return { ok: true, user: { name: matched } }
})