summaryrefslogtreecommitdiff
path: root/features/webui_login
AgeCommit message (Collapse)AuthorFilesLines
2026-03-25Fix routes missing trailing slashDavy Marrero1-2/+2
bmcweb's route handler generates handlers for both /foo/ and /foo when a route is registered with a trailing slash. This change adds trailing slashes to 24 routes that were missing them. Existing clients are not affected: the router already accepted both forms. This change makes the route registrations consistent and lets the trailing-slash ast-grep rule pass without suppressions. Routes using <path> captures already match everything and do not need a trailing slash, so those are excluded in the ast-grep rule. Tested: ast-grep scan --error exits 0. Change-Id: I9de641bd8ffec773b313b7e4da9034be0fd7e8e8 Signed-off-by: Davy Marrero <dmarrero@nvidia.com>
2026-02-03Remove old login routinesEd Tanous1-158/+49
At one point the bmcweb /login route has supported a bunch of different login mechanisms: 1. Sending username and password via headers, mirroring a non-openbmc implementation that has never been used in openbmc, and predates this repo being called bmcweb. 2. Sending username and password under a "data" object, mirroring phosphor-rest json webserver. 3. Sending username and password as an http multipart as part of the initial multipart parser patch. 4. Sending a json payload as {"username": <>, "password": <>} This commit removes all but the final login mechanism. Redfish login has been used exclusively for many many years, and only the webui used 4 above up until a few years ago in commit 1ff8e89fd2397c468ab0237158e5aeeff2692413 Keeping one viable login mechanism that's not Redfish is useful in the future if there are those that want to disable Redfish. All others could potentially be security issues, so keeping the code simple and conscise here is ideal. This commit does not attempt to make a backwards compatibility path, under the assumption that other than 4, none of the other code was ever used in any real capacity. If we find that to not be true, we can add back the portions where we need compatibility, but this seems unlikely. Tested: WIP Change-Id: I04b4968836f0f824f46b3dff180ad92feb16967c Signed-off-by: Ed Tanous <etanous@nvidia.com>
2026-01-30Remove usages of nlohmann::json::begin()Ed Tanous1-45/+53
nlohmann::json::begin() throws an uncaught exception. Tested: Redfish service validator passes. Signed-off-by: Ed Tanous <ed@tanous.net> Change-Id: I08244b0787cd4d6e592b0731196490a5160aba62
2025-06-27Rearrange featuresEd Tanous2-0/+228
The backends are different things compared to generic code. Today, these are all included in the /include folder, but it's not very clear what options control which backends, or how things map together. This also means that we can't separate ownership between the various companies. This commit is a proposal to try to create a features folder, separated by the code for the various backends, to make interacting with this easier. It takes the form features/<option name>/files.hpp features/<option name>/files_test.hpp Note, redfish-core was already at top level, and contains lots of code, so to prevent lots of conflicts, it's simply symlinked into that folder to make clear that it is a backend, but not to move the implementation and cause code conflicts. Tested: Unit tests pass. Code compiles. Change-Id: Idcc80ffcfd99c876734ee41d53f894ca5583fed5 Signed-off-by: Ed Tanous <etanous@nvidia.com>