Skip to documentation content

Auth

Auth

Request-scoped state produced by {% auth %} commands during login, registration, and related flows.

{{ auth }} holds the result of {% auth %} methods on the current request: whether init ran, which profile the commands target, login success, error codes, and flags such as locked or registered. It is not the signed-in {{ profile }} — auth.logged_in and the global profile object describe that session.

{% auth %} methods write this object. {% logout %} ends a signed-in profile session. Those methods are documented under Methods Overview → Auth.

{{ auth }}

Stores information about the current state of profile authorization, which is the result of calls to the {% auth %} methods.

Properties
Properties of {{ auth }} objects
Name Type Description
object_type string Will always be auth
is_valid boolean Will be true if an {% auth init %} method has been called
init boolean Will be true if an {% auth init %} method has been called
id string The identifier used by the {% auth init %} method
exists boolean Will be true if the profile referenced by the {% auth init %} method has been created
profile {{ profile }} The profile that auth commands are currently being executed for. Note that this profile may or may not have been created yet
error_code string A short error code that can be used to identify the type of error caused by the last call to a {% auth %} method.
error_message string A longer description containing details about the error caused by the last call to a {% auth %} method.
logged_in boolean Whether or not the user is currently logged in to a profile (identified by the global {{ profile }} variable)
login_success boolean Will be true if the {% auth login %} method was called and was successful
aborted boolean Will be true if the {% auth abort %} method was called
can_abort boolean Will be true if it is possible to use the {% auth abort %} method
password_changed boolean Will be true if an auth method was used to set or change a profile's password
id_changed boolean Will be true if an auth method was used to set or change a profile's id
old_id string If auth methods were used to change the id of a profile, old_id will contain the original id before it was changed
new_id string If auth methods were used to change the id of a profile, new_id will contain the final id after it was changed
email_changed boolean Will be true if an auth method was used to set or change a profile's email address
old_email string If auth methods were used to change the email address of a profile, old_email will contain the original email address before it was changed
new_email string If auth methods were used to change the email address of a profile, new_email will contain the final email address after it was changed
force_password_reset boolean Will be true if {% auth force_password_reset %} was called successfully or if {% auth register %} was called successfully and the password must be reset on the new profile
activation_code_set boolean Will be true if {% auth set_activation_code %} was called successfully or if {% auth register %} was called successfully and the new profile requires activation
new_activation_code string If {% auth set_activation_code %} was called successfully or if {% auth register %} was called successfully and the new profile requires activation, new_activation_code will contain the activation code that should be used to activate the new profile
activation_code_expires {{ time }} If {% auth set_activation_code %} was called successfully or if {% auth register %} was called successfully and the new profile requires activation, activation_code_expires will contain the date and time that the new activation code will expire
activated boolean Will be true if {% auth activate %} was called successfully or if {% auth register %} was called successfully and the new profile is already activated
deactivated boolean Will be true if {% auth deactivate %} or {% auth set_activation_code %} (which also automatically deactivates the profile) was called successfully
locked boolean Will be true if {% auth lock %} was called successfully
unlocked boolean Will be true if {% auth unlock %} was called successfully
locked_until {{ time }} If {% auth lock %} was called successfully, locked_until will contain the date and time that the profile will no longer be locked
blocked boolean Will be true if {% auth block %} was called successfully
unblocked boolean Will be true if {% auth unblock %} was called successfully
registered boolean Will be true if {% auth register %} was called successfully
output string A json representation of the current auth object
Example Get POST (form) parameters from the requestRead form or POST body parameters from request.post_params for use in the template.
Liquid
{%- if request.post_params.is_valid -%}
  {%- assign var username = request.post_params['username'] -%}
  {%- assign var password = request.post_params['password'] -%}
  {%- if username is_valid and password is_valid -%}
	{%- auth login username password -%}
  {%- endif -%}
{%- endif -%}
{%- unless auth.logged_in -%}
  <p>Could not log in</p>
{%- endunless -%}