main
|
Last change
on this file was b715712, checked in by Stefan <trsunovstefan@…>, 8 weeks ago |
|
Add the server side and configuration
|
-
Property mode
set to
100644
|
|
File size:
1.1 KB
|
| Line | |
|---|
| 1 | # Use-case 0002 — Log in
|
|---|
| 2 |
|
|---|
| 3 | **Initiating actor:** Visitor
|
|---|
| 4 |
|
|---|
| 5 | **Other actors:** —
|
|---|
| 6 |
|
|---|
| 7 | A registered user authenticates so the system can treat subsequent actions as a Trader.
|
|---|
| 8 |
|
|---|
| 9 | ## Scenario
|
|---|
| 10 |
|
|---|
| 11 | 1. Visitor chooses "Login" from the anonymous menu.
|
|---|
| 12 | 2. System prompts for username and password.
|
|---|
| 13 | 3. Visitor enters values.
|
|---|
| 14 | 4. System looks up the user:
|
|---|
| 15 |
|
|---|
| 16 | ```sql
|
|---|
| 17 | SELECT id, password_hash
|
|---|
| 18 | FROM project.users
|
|---|
| 19 | WHERE username = $1;
|
|---|
| 20 | ```
|
|---|
| 21 | 5. If no row is returned, system responds "Invalid credentials." and scenario ends.
|
|---|
| 22 | 6. If a row is returned, system compares the stored hash against sha256 of the entered password. On mismatch it responds "Invalid credentials." and ends.
|
|---|
| 23 | 7. On match, system records the returned `id` and username in the session and displays the authenticated menu.
|
|---|
| 24 |
|
|---|
| 25 | ### Alternate flow 4a — authenticated lookup with live balance
|
|---|
| 26 |
|
|---|
| 27 | The system may combine identity lookup with live balance in a single query, for use cases that need both:
|
|---|
| 28 |
|
|---|
| 29 | ```sql
|
|---|
| 30 | SELECT id, available_balance, invested_balance
|
|---|
| 31 | FROM project.users
|
|---|
| 32 | WHERE username = $1
|
|---|
| 33 | AND password_hash = encode(digest($2, 'sha256'), 'hex');
|
|---|
| 34 | ```
|
|---|
Note:
See
TracBrowser
for help on using the repository browser.