Sign-in for your site
Email and password accounts for your visitors, with hosted pages on your own address.
Every site Lahyer hosts can let its visitors create an account and sign in, without a backend of your own. Lahyer serves the pages under /.lahyer/auth/ on your site's own address, keeps the accounts per project and lists them on the project's Users tab. Apps made in Lahyer Studio add sign-in when you ask.
These accounts belong to your site. They are separate from Lahyer accounts, and your visitors never see Lahyer's dashboard.
Link to the hosted pages
| Path | Page |
|---|---|
/.lahyer/auth/sign-up | Create an account |
/.lahyer/auth/sign-in | Sign in |
/.lahyer/auth/forgot | Ask for a password reset link |
/.lahyer/auth/sign-out | Sign out |
Add ?next= with a path on your site to bring the visitor back there afterwards. Use plain links rather than your framework's router links: these pages are not routes of your app.
<a href="/.lahyer/auth/sign-in?next=/account">Sign in</a>
<a href="/.lahyer/auth/sign-up?next=/account">Create an account</a>
<a href="/.lahyer/auth/sign-out?next=/">Sign out</a>New accounts get an email to verify their address, and the reset link arrives by email too.
Who is signed in
GET /.lahyer/auth/me answers with the visitor, or null when nobody is signed in:
{
"user": {
"id": "stu_8kq2...",
"email": "ada@example.com",
"name": "Ada",
"emailVerified": true
}
}In the browser, the session cookie goes along by itself:
const { user } = await fetch("/.lahyer/auth/me").then((response) => response.json());On your server, pass the visitor's session cookie on. With the Next.js App Router:
import { cookies, headers } from "next/headers";
export type SiteUser = { id: string; email: string; name: string | null; emailVerified: boolean };
export async function currentUser(): Promise<SiteUser | null> {
const session = (await cookies()).get("__Host-lahyer_session")?.value;
const h = await headers();
const host = h.get("x-forwarded-host") ?? h.get("host");
if (!session || !host) return null;
const response = await fetch(`https://${host}/.lahyer/auth/me`, {
headers: { cookie: `__Host-lahyer_session=${session}` },
cache: "no-store",
});
if (!response.ok) return null;
return ((await response.json()) as { user: SiteUser | null }).user;
}Members-only pages call currentUser() and redirect to /.lahyer/auth/sign-in?next=/the-page when it returns null. Keep each person's data under their user.id.
Sessions and security
- The session is the
__Host-lahyer_sessioncookie: secure, bound to your site's hostname, valid for 30 days and renewed as the visitor keeps using the site. - Passwords are 8 to 128 characters.
- Ten failed sign-ins for one email address pause sign-in for that address for 15 minutes.
- Sign-up, sign-in and the other forms only accept requests from your site's own pages.
- Verification links last 48 hours, password reset links 60 minutes.
Managing accounts
The project's Users tab lists the accounts with their sign-up and last sign-in dates. Search by email, and disable, enable or delete an account; owners and admins can make changes. Disabling or deleting an account signs it out everywhere.
Limits
- 5,000 accounts per site, and 30 sign-ups an hour.
- Three emails an hour to any one address.
- Ten requests a minute from one visitor to the sign-in, sign-up and other forms.
Sign-in with Google, GitHub or other providers is not available yet.