35 lines
1.5 KiB
Markdown
35 lines
1.5 KiB
Markdown
## ADDED Requirements
|
|
|
|
### Requirement: Account registration
|
|
The system SHALL allow a new owner to register with a unique email address and a password. The password SHALL be stored only as a salted hash.
|
|
|
|
#### Scenario: Successful registration
|
|
- **WHEN** a visitor submits a new email and password on the register page
|
|
- **THEN** an account is created and the visitor is logged in
|
|
|
|
#### Scenario: Duplicate email
|
|
- **WHEN** a visitor registers with an email that already exists
|
|
- **THEN** registration is rejected with an error message
|
|
|
|
### Requirement: Login and logout
|
|
The system SHALL allow an owner to log in with email and password and to log out, maintaining an authenticated session via a signed session cookie.
|
|
|
|
#### Scenario: Successful login
|
|
- **WHEN** an owner submits the correct email and password
|
|
- **THEN** a session cookie is set and the owner is authenticated
|
|
|
|
#### Scenario: Incorrect password
|
|
- **WHEN** an owner submits a wrong password
|
|
- **THEN** login is rejected with an error message and no session is created
|
|
|
|
#### Scenario: Logout
|
|
- **WHEN** an authenticated owner clicks logout
|
|
- **THEN** the session is destroyed and the owner is redirected to the home page
|
|
|
|
### Requirement: Session-protected routes
|
|
Routes that manage tags SHALL require an authenticated session and redirect unauthenticated visitors to the login page.
|
|
|
|
#### Scenario: Unauthenticated access to account
|
|
- **WHEN** a visitor who is not logged in opens the account page
|
|
- **THEN** they are redirected to the login page
|