Login
Route
/login
Page Purpose
Let the user authenticate with a username and password to open a session in the app.
Fields on the Page
- The "Platform" text wordmark.
- A lockout alert (with remaining wait time) when locked out.
- A failed-attempts/remaining-attempts alert (before lockout).
- A generic error alert (invalid credentials/network error, etc.).
- A form: Username field, Password field (masked), a "Giriş Yap" (Sign In) submit button (visually switches to a "filled" state once both fields are non-empty).
User Actions
- Enter username and password.
- Click "Giriş Yap" or submit the form.
- On success, automatically navigate to the Platforms page (
/platform). - After three failed attempts, the form locks for 30 seconds; once the lockout expires, retries are automatically allowed again.
Data Used
token,user, and an optionalusernamefield returned by the backend (see API Documentation › Authentication).- If a valid session already exists (Redux
adminstate is populated), the page never renders and redirects to/platformimmediately.
Access and Visibility
Public — no session required. Users who already have a session never see this page; they are redirected automatically.
Components Used
dashboard/src/components/auth/Login.tsx— the page's main component.dashboard/src/components/auth/AuthLayout.tsx— the sidebar-less page chrome specific to the login screen.dashboard/src/components/hooks/useLoginLockout.tsx— the 30-second lockout logic after 3 failed attempts.dashboard/src/services/authService.tsx— the real backend login request (loginRequest).dashboard/src/services/auditService.tsx— logs a successful login to the audit log (logPlatformStep, in the background, does not affect the page flow).
API Communication
| Action | Method | Endpoint | Purpose |
|---|---|---|---|
| Sign in | POST | /login |
Validate username/password, obtain a JWT token |
| Login audit record | POST | /iqv_platform_log |
Records a successful login to the audit log (in the background; failures are never surfaced to the user) |
For the detailed request/response contract, see API Documentation › Authentication.
State Management
- Form fields: local React state (
useState,Form.useForm). - Login lockout (attempt count, lockout end time):
localStorage(iqv_login_attempts,iqv_login_lockout_until) — not in Redux. - The session, once login succeeds: written to the Redux
adminslice and persisted tolocalStorageviaredux-persist(under thepersist:IQV Platformkey);token/userare also written directly tolocalStoragefor legacy compatibility.