Files
jobtrackingapp/docs/auth/login.md
T
cesnimda ce76046a29 feat: complete release readiness work
- consolidate API ownership and remove dead vendor code

- add Stripe billing, learning paths, and public CV hardening

- add migration, recovery, security, audit, and browser gates
2026-07-31 16:54:16 +02:00

536 B

login

POST /api/auth/login accepts email, password, and remember-me preference. Successful local login issues an HttpOnly session cookie plus a readable CSRF cookie. Accounts with two-factor authentication receive a short-lived pending token and must complete POST /api/auth/2fa/challenge before a session is issued. Login and challenge endpoints are rate-limited.

The frontend route is /login; registration has its own /register route. Authentication errors are shown without exposing whether an unknown account exists.