The password gate's pages — deliberately plain: a visitor who does not know the password sees a blank page with one field and nothing else, no site name, no login, no layout.
GET <prefix>/access— the prompt (?to=is where the visitor was going: a path on this site, checked before use).POST <prefix>/access— one try. The lockout is checked first; a try while locked is recorded as such and never judged. A right answer unlocks the session and sends the visitor on.GET <prefix>/access/link/:token— the access link a client was given: a page with one button, so opening the link (a preview fetcher, a chat client) does not by itself unlock anything.POST <prefix>/access/link/:token— the button: unlocks when the token is current.GET <prefix>/access/status— answersokwhile everything else is locked, for an uptime check.
These routes are exempt from the gate itself (see
PhoenixKitWeb.Plugs.WebsiteAccess).