source: docs/P3-UseCaseModel/UseCase0002.md@ 9577c79

main
Last change on this file since 9577c79 was b715712, checked in by Stefan <trsunovstefan@…>, 8 weeks ago

Add the server side and configuration

  • Property mode set to 100644
File size: 1.1 KB
RevLine 
[d8ce4e2]1# Use-case 0002 — Log in
2
3**Initiating actor:** Visitor
4
5**Other actors:** —
6
7A registered user authenticates so the system can treat subsequent actions as a Trader.
8
9## Scenario
10
111. Visitor chooses "Login" from the anonymous menu.
122. System prompts for username and password.
133. Visitor enters values.
144. System looks up the user:
15
16 ```sql
17 SELECT id, password_hash
18 FROM project.users
19 WHERE username = $1;
20 ```
215. If no row is returned, system responds "Invalid credentials." and scenario ends.
226. If a row is returned, system compares the stored hash against sha256 of the entered password. On mismatch it responds "Invalid credentials." and ends.
237. On match, system records the returned `id` and username in the session and displays the authenticated menu.
24
25### Alternate flow 4a — authenticated lookup with live balance
26
27The system may combine identity lookup with live balance in a single query, for use cases that need both:
28
29```sql
30SELECT id, available_balance, invested_balance
31 FROM project.users
32 WHERE username = $1
33 AND password_hash = encode(digest($2, 'sha256'), 'hex');
34```
Note: See TracBrowser for help on using the repository browser.