model/auth Cotonic

Owns browser authentication state and communicates with /zotonic-auth. It checks and refreshes authentication, manages login/logout and password operations, and synchronizes with other tabs. Use the authentication worker loaded by Zotonic's normal page setup.

Commands

All topics below start with model/auth/. Unless stated otherwise, use publish and observe the events below; commands do not return a direct reply.

Topic suffixPayload and behavior
post/checkRecheck authentication; payload is ignored.
post/refreshRefresh authentication, passing the payload as refresh options.
post/logonusername, password, optional passcode, rememberme, code-new, and test_passcode.
post/form/logonCotonic form payload: credentials under value; message.username overrides value.username when non-empty. Also accepts value.is_username_check, value.authuser, and value.onauth.
post/logoffLog out; payload is ignored.
post/switch-user{ user_id: ... }; the server determines whether the switch is authorized.
post/onetime-token{ token: ..., url: ... } for an authentication handoff.
post/reset-code-checkusername, secret, and optional passcode. Supports a response topic and returns the server's reset-check response.
post/resetusername, secret, new password, optional passcode, rememberme, onauth, code-new, and test_passcode.
post/changeCurrent password, new password_reset, optional passcode, onauth, code-new, and test_passcode.
cotonic.broker.publish("model/auth/post/check", {});

Only the reset-code check explicitly supports a direct call:

cotonic.broker.call("model/auth/post/reset-code-check", {
    username: "reader",
    secret: resetSecret
}).then(function(msg) {
    console.log("Reset check:", msg.payload);
});

A fetch failure for that operation replies with { result: "error", error: "fetch" }.

Events

All event topics start with model/auth/.

Topic suffixPayloadRetained
event/authAuthentication state, including status, is_authenticated, user_id, username, and preferences.Yes
event/auth-user-idCurrent user ID when the worker enters its known-authentication state.No
event/auth-changing{ onauth, auth } during an authentication transition.No
event/auth-error{ error, data }.No
event/auth-change-resultServer result of a password-change request.No
event/ui-status{ classes, status: { auth: "user" or "anonymous" } }.No
event/ping"pong" after subscriptions are installed.Yes
cotonic.broker.subscribe("model/auth/event/auth", function(msg) {
    const auth = msg.payload;
    console.log("Authenticated:", auth.is_authenticated);
});

The worker listens to model/ui/event/recent-activity for keep-alive decisions, model/sessionStorage/event/auth-user-id for user changes, and model/serviceWorker/event/broadcast/auth-sync for cross-tab checks. Its advertised dependencies are cotonic#sessionStorage, cotonic#localStorage, and cotonic#sessionId.

Client state describes the interface's current view of authentication. Server models and actions still enforce their own access control.

Implementation

JavaScript source.

Edit on GitHub