Signing in and out
The reference frontend keeps the learner’s API token in an httpOnly cookie (ulams_session,
SameSite=Lax), set by the server. Scripts in the page never see the token. See
authentication for the API side.
Sign-in page
Section titled “Sign-in page”
/login has two forms:
- E-mail and password. Calls the tenant’s
POST /api/auth/login. A wrong e-mail or password shows “Wrong e-mail or password.”; any other failure shows “Login failed. Try again.” - Continue as the demo student. Signs in as the tenant’s demo student, the same way automatic sign-in does (below).
After signing in the learner goes to the page in the next query parameter (only paths on the
same site are accepted), or to /. Pages that need a session send the learner to
/login?next=<page> when no session can be created.
There is no registration or password-reset page in the reference frontend; those exist only in
the legacy React app (/register, /reset-password).
Automatic sign-in
Section titled “Automatic sign-in”When a learner without a session opens a page under /learn/ or /account (or a browser island
calls the BFF), the server signs them in as the tenant’s demo student:
- If the tenant has demo mode on, it calls
POST /api/demo/loginwith{"role": "student"}. - Otherwise it logs in with
DEMO_STUDENT_EMAIL(defaultstudent1@{slug}.ulams.app) andDEMO_STUDENT_PASSWORDfrom the frontend’s server environment. - If neither works, the page redirects to
/login.
The resulting token is cached on the server per tenant and shared by all visitors, so every visitor of a demo tenant is the same student and shares that student’s progress. When the token stops working after the hourly demo reset, the next lesson request signs in again once.
On demo tenants a “Demo - resets hourly” badge explains this: “You are logged in as a demo student. Everything you do is wiped every hour.” See demo academies.
Signing out
Section titled “Signing out”/logout accepts only POST. It deletes the session cookie and redirects to /. The
account page has the “Log out” button. The API token itself is not
revoked.
On a demo tenant, opening a lesson again signs the visitor straight back in as the demo student.