ce76046a29
- consolidate API ownership and remove dead vendor code - add Stripe billing, learning paths, and public CV hardening - add migration, recovery, security, audit, and browser gates
10 lines
536 B
Markdown
10 lines
536 B
Markdown
# login
|
|
|
|
`POST /api/auth/login` accepts email, password, and remember-me preference. Successful local login
|
|
issues an HttpOnly session cookie plus a readable CSRF cookie. Accounts with two-factor authentication
|
|
receive a short-lived pending token and must complete `POST /api/auth/2fa/challenge` before a session is
|
|
issued. Login and challenge endpoints are rate-limited.
|
|
|
|
The frontend route is `/login`; registration has its own `/register` route. Authentication errors are
|
|
shown without exposing whether an unknown account exists.
|