# Login form for Jekyll site

**URL:** <https://talk.jekyllrb.com/t/login-form-for-jekyll-site/7268>\
**Category:** Help\
**Created:** [April 26, 2022, 11:59pm UTC](https://talk.jekyllrb.com/t/login-form-for-jekyll-site/7268 "2022-04-26T23:59:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![JackieGable](https://yyz2.discourse-cdn.com/flex030/user_avatar/talk.jekyllrb.com/jackiegable/32/4300_2.png) [@JackieGable](https://talk.jekyllrb.com/u/JackieGable)\
**Post date:** [April 26, 2022, 11:59pm UTC](https://talk.jekyllrb.com/t/login-form-for-jekyll-site/7268/1 "2022-04-26T23:59:15Z")

</div>

I’m curious if anyone here has figured out how to implement a login form for a membership section of a jekyll website. Since there isn’t a database, how can a login form (with a username and password) be used to limit access to a specific area of a Jekyll website? Thanks a bunch for helping!!!

---

<div class="post-metadata">

**Author:** ![fabiomux](https://yyz2.discourse-cdn.com/flex030/user_avatar/talk.jekyllrb.com/fabiomux/32/2656_2.png) [@fabiomux](https://talk.jekyllrb.com/u/fabiomux)\
**Post date:** [April 27, 2022, 8:20am UTC](https://talk.jekyllrb.com/t/login-form-for-jekyll-site/7268/2 "2022-04-27T08:20:49Z")

</div>

You have to play with _basic authentication_:

- Nginx: [Restricting Access with HTTP Basic Authentication | NGINX Plus](https://docs.nginx.com/nginx/admin-guide/security-controls/configuring-http-basic-authentication/)
- Apache: [Authentication and Authorization - Apache HTTP Server Version 2.4](https://httpd.apache.org/docs/2.4/howto/auth.html)

However to register the user you need some sort of server-side script, let’s say PHP:

- to generate the password in the auth file directly;
- to send an email to a specific address that can be read from a script in your local server that parses the message and _generates & loads_ the auth file (in that case also Javascript in place of PHP might be a good solution).

---

<div class="post-metadata">

**Author:** ![BastienDurel](https://yyz2.discourse-cdn.com/flex030/user_avatar/talk.jekyllrb.com/bastiendurel/32/4543_2.png) [@BastienDurel](https://talk.jekyllrb.com/u/BastienDurel)\
**Post date:** [April 28, 2022, 9:04am UTC](https://talk.jekyllrb.com/t/login-form-for-jekyll-site/7268/3 "2022-04-28T09:04:42Z")

</div>

You may play with something like [mod\_oauth2](https://github.com/zmartzone/mod_oauth2) or [mod\_auth\_openidc](https://github.com/zmartzone/mod_auth_openidc) for apache to delegate the authentication to an external openid/oauth2 server (did not try, I’ll let you dig in ;))

---

<div class="post-metadata">

**Author:** ![ckruse](https://yyz2.discourse-cdn.com/flex030/user_avatar/talk.jekyllrb.com/ckruse/32/16_2.png) [@ckruse](https://talk.jekyllrb.com/u/ckruse)\
**Post date:** [April 28, 2022, 9:33pm UTC](https://talk.jekyllrb.com/t/login-form-for-jekyll-site/7268/4 "2022-04-28T21:33:45Z")

</div>

MongoDB (the company) has a product, MongoDB Realm, that can handle user authentication for static sites. It used to be called MongoDB Stitch.

I tested it extensively a few years ago on a large Jekyll site, and it fit my use case perfectly. That project used MongoDB upstream of the Jekyll build, so the decision was easy. It also has a decent free tier. It may be far more than you need though (see basic auth suggestions above).

The Realm ecosystem has grown considerably since those early days - you want the Web SDK (link below).

I believe Netlify now has an [Identity](https://docs.netlify.com/visitor-access/identity/) product, and I suspect several other JAMstack companies have jumped on the bandwagon as well. The search term you want to Google is “adding dynamic components to a static site”…add “authentication” to the end to drill down.

> **[Realm Web Quick Start — MongoDB Realm](https://www.mongodb.com/docs/realm/web/quickstart/)**

---

<div class="post-metadata">

**Author:** ![clarabennett](https://yyz2.discourse-cdn.com/flex030/user_avatar/talk.jekyllrb.com/clarabennett/32/5981_2.png) [@clarabennett](https://talk.jekyllrb.com/u/clarabennett)\
**Post date:** [June 19, 2024, 3:59pm UTC](https://talk.jekyllrb.com/t/login-form-for-jekyll-site/7268/5 "2024-06-19T15:59:11Z")

</div>

Hello,  
I thing you can use JavaScript to handle form submission and validate credentials. You can perform basic client-side validation to ensure fields are not empty before submission. You can also create layouts that check if users are authenticated before displaying sensitive content.

Thanks

---

<div class="post-metadata">

**Author:** ![VillyVretthorn](https://avatars.discourse-cdn.com/v4/letter/v/a587f6/32.png) [@VillyVretthorn](https://talk.jekyllrb.com/u/VillyVretthorn)\
**Post date:** [June 19, 2024, 4:19pm UTC](https://talk.jekyllrb.com/t/login-form-for-jekyll-site/7268/6 "2024-06-19T16:19:52Z")

</div>

So, I have a different angle on this. IF what you want to limit access to is something simple as a file to download, etc. and you can accept a single shared password to that file then you might just do something like having the file stored in /restricted//document.pdf

Then you create a password form that uses javascript to calculate the (salted) sha256 of the provided password and then redirects the user to the url /restricted//document.pdf  
Now, either this URL exists (if the hash is correct) or it does not.  
If it exists, the user will then download the file. If not, the user will see an error. This will be a 404 error. You may want to customize the 404 error page for /restricted/ to say something like “Incorrect password” And a link back to the form.

Please note that this is obviously not high level security. But it is often Good Enough™ and it is purely static/client side.

This may or may not fit your use case. But wanted to throw the idea out there as I have used this with success on several projects.
