Skip to content

Commit bf55db2

Browse files
Merge pull request #350 from appdevforall/feat/ADFA-5043-calibre-remember-me
ADFA-5043: Calibre-Web auto-login via Flask-Login remember_token (dash-node 1.1.4)
2 parents c0fd8e2 + 55168f4 commit bf55db2

4 files changed

Lines changed: 8 additions & 3 deletions

File tree

‎static/dashboard/CHANGELOG.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@ One line per version, newest first. Every REST-facing change bumps the version i
44
(the app surfaces it via `/system/dashboard/update-check` and the "Update available" pill), so this
55
file is the human record of what each bump enables. Keep entries short: `version - change (TICKET)`.
66

7+
- **1.1.4** - Calibre-Web auto-login: send Flask-Login `remember_me` so the session includes a persistent `remember_token`, which sticks in the WebView despite anonymous/guest browsing. (ADFA-5043)
78
- **1.1.3** - `/auth/:service/session`: server-side login returning the session cookie, for WebView auto-login as box admin (Calibre-Web / Kolibri). (ADFA-5043)
89
- **1.1.2** - ZIM download URL built from the project subdir (`/zim/<project>/<file>`), so non-Wikipedia ZIMs download instead of 404ing. Pairs with the app sending `<project>/<file>`. (ADFA-5042)
910
- **1.1.1** - `/system/dashboard/update-check`: reports installed vs. latest so the card can show "Up to date / Update available". (ADFA-5026)

‎static/dashboard/package-lock.json‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎static/dashboard/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "dashboard-console",
3-
"version": "1.1.3",
3+
"version": "1.1.4",
44
"description": "",
55
"main": "index.js",
66
"scripts": {

‎static/dashboard/sockets/books.query.ts‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -120,6 +120,10 @@ export async function getCalibreSession(): Promise<{ cookie: string; csrfToken:
120120
const cred = getCredential('calibre');
121121
loginData.append('username', cred.username);
122122
loginData.append('password', cred.password);
123+
// ADFA-5043: request Flask-Login's persistent "remember me" so the response also sets a
124+
// `remember_token` cookie. Calibre-Web allows anonymous (guest) browsing, so the session cookie
125+
// alone doesn't stick in the WebView; the remember_token re-authenticates as admin reliably.
126+
loginData.append('remember_me', 'on');
123127

124128
const authRes = await fetch(`${CALIBRE_WEB_LOCAL_URL}/login`, {
125129
method: 'POST',

0 commit comments

Comments
 (0)