Skip to content

Login

Route

/login

Page Purpose

Let the user authenticate with a username and password to open a session in the app.

Fields on the Page

  • The "Platform" text wordmark.
  • A lockout alert (with remaining wait time) when locked out.
  • A failed-attempts/remaining-attempts alert (before lockout).
  • A generic error alert (invalid credentials/network error, etc.).
  • A form: Username field, Password field (masked), a "Giriş Yap" (Sign In) submit button (visually switches to a "filled" state once both fields are non-empty).

User Actions

  1. Enter username and password.
  2. Click "Giriş Yap" or submit the form.
  3. On success, automatically navigate to the Platforms page (/platform).
  4. After three failed attempts, the form locks for 30 seconds; once the lockout expires, retries are automatically allowed again.

Data Used

  • token, user, and an optional username field returned by the backend (see API Documentation › Authentication).
  • If a valid session already exists (Redux admin state is populated), the page never renders and redirects to /platform immediately.

Access and Visibility

Public — no session required. Users who already have a session never see this page; they are redirected automatically.

Components Used

  • dashboard/src/components/auth/Login.tsx — the page's main component.
  • dashboard/src/components/auth/AuthLayout.tsx — the sidebar-less page chrome specific to the login screen.
  • dashboard/src/components/hooks/useLoginLockout.tsx — the 30-second lockout logic after 3 failed attempts.
  • dashboard/src/services/authService.tsx — the real backend login request (loginRequest).
  • dashboard/src/services/auditService.tsx — logs a successful login to the audit log (logPlatformStep, in the background, does not affect the page flow).

API Communication

Action Method Endpoint Purpose
Sign in POST /login Validate username/password, obtain a JWT token
Login audit record POST /iqv_platform_log Records a successful login to the audit log (in the background; failures are never surfaced to the user)

For the detailed request/response contract, see API Documentation › Authentication.

State Management

  • Form fields: local React state (useState, Form.useForm).
  • Login lockout (attempt count, lockout end time): localStorage (iqv_login_attempts, iqv_login_lockout_until) — not in Redux.
  • The session, once login succeeds: written to the Redux admin slice and persisted to localStorage via redux-persist (under the persist:IQV Platform key); token/user are also written directly to localStorage for legacy compatibility.