Skip to content
YAADMIN
Download

APPLICATION REFERENCE

Authentication API

4 verified authentication routes: authentication, fields, responses, errors and approval boundaries.

PartialSource snapshot · 2026-10-02

Application boundary#

These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.

Verified routes#

4 routes

GET/login

Login page.

Authentication
public
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
next=None
Headers
none beyond shared session/CSRF
Response structure
RedirectResponse(url=_safe_next(next), status_code=303); HTML template response (handler names the template)
Important errors
303
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler login_page. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/auth/login

Login.

Authentication
public
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
LoginPayload [username, password, provider, next, ui_language]
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok, username, display_name, next}
Important errors
400, 401, 429, 503
Approval behavior
no standalone approval behavior in this handler.

Request fields

FieldVerified definition
usernamestr = Field(min_length=1, max_length=255)
passwordtype/default redacted; field name verified
providerstr = Field(default="local", min_length=1, max_length=32)
nextstr | None = Field(default=None, max_length=2048)
ui_languagestr | None = Field(default=None, min_length=2, max_length=8)

Verified route registration · handler api_login. Some definitions may be partially redacted; no missing fields are inferred.

POST/api/auth/logout

Logout.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{ok}
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_logout. Some definitions may be partially redacted; no missing fields are inferred.

GET/api/auth/session

Auth session.

Authentication
session
Permission
no separate permission identifier in handler (admin/owner/runtime checks as above)
Request body
none
Query parameters
none explicitly read
Headers
none beyond shared session/CSRF
Response structure
{authenticated, username, display_name, source, auth_provider, roles, is_web_admin}
Important errors
none literal; shared/helper errors apply
Approval behavior
no standalone approval behavior in this handler.

Verified route registration · handler api_auth_session. Some definitions may be partially redacted; no missing fields are inferred.

Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.

Search documentation

Search stays in your browser.