# Bypass login for localhost environment

**URL:** <https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015>\
**Category:** Questions\
**Tags:** v2\
**Created:** [January 12, 2016, 6:52am UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015 "2016-01-12T06:52:17Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![jenstornell](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/jenstornell/32/546_2.png) [@jenstornell](https://forum.getkirby.com/u/jenstornell)\
**Post date:** [January 12, 2016, 6:52am UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/1 "2016-01-12T06:52:17Z")

</div>

Is there a simple way to skip the login process for localhost environment? Like, I go to [http://localhost/kirby/panel/](http://localhost/kirby/panel/) not need to fill in the login form?

---

<div class="post-metadata">

**Author:** ![flokosiol](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/flokosiol/32/468_2.png) [@flokosiol](https://forum.getkirby.com/u/flokosiol)\
**Post date:** [January 12, 2016, 9:48am UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/2 "2016-01-12T09:48:33Z")

</div>

My idea was to set `panel.session.lifetime` to invinite (0) and increase `panel.session.timeout`, but this didn’t work for me …

in site/config/config.php

```auto
c::set('panel.session.lifetime', 0);
c::set('panel.session.timeout', 2160); // 36 hours

```

---

<div class="post-metadata">

**Author:** ![jenstornell](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/jenstornell/32/546_2.png) [@jenstornell](https://forum.getkirby.com/u/jenstornell)\
**Post date:** [January 12, 2016, 9:52am UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/3 "2016-01-12T09:52:21Z")

</div>

Doesn’t the session die when browser is closed? I’m hoping for a solution that works even if I restart my computer.

I bet this is a hard nut to crack.

Nice try anyway! 🙂

---

<div class="post-metadata">

**Author:** ![gerardkd](https://avatars.discourse-cdn.com/v4/letter/g/e56c9b/32.png) [@gerardkd](https://forum.getkirby.com/u/gerardkd)\
**Post date:** [January 12, 2016, 9:55am UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/4 "2016-01-12T09:55:52Z")

</div>

I haven’t tested this, but can’t you fix it by creating a custom route with this url ( you can use config.localhost to only apply this logic on your dev environment, see here, under ‘multi environment options’ : [http://getkirby.com/docs/advanced/options](http://getkirby.com/docs/advanced/options) ), log the admin user in at the ‘action’ and then `go('/panel')` ?

Again, I didn’t test this, just thinking out loud! 🙂

**Edit** Now that I look somewhat further in the documentation, I don’t know this will work because you need to return something, the ‘go’ in this example, but you also need to execute the ‘login’ part. Sorry 🙂

---

<div class="post-metadata">

**Author:** ![flokosiol](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/flokosiol/32/468_2.png) [@flokosiol](https://forum.getkirby.com/u/flokosiol)\
**Post date:** [January 12, 2016, 10:12am UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/5 "2016-01-12T10:12:54Z")

</div>

This works for me …

```auto
c::set('routes', array(
  array(
    'pattern' => 'autologin',
    'action' => function() {
      $username = 'YOURUSERNAME';
      $password = 'YOURPASSWORD';
      
      // Prevent access on the production system
      if(url::host() !== 'localhost') return false;
      
      $user = site()->user($username);
      if($user and $user->login($password)) {
        go('panel'); // or use go(); to redirect to the frontpage
      } else {
        echo 'invalid username or password';
        return false;
      }

    }
  )
));

```

Adjust `$username` and `$password` and visit [http://yoursite.tld/autologin](http://yoursite.tld/autologin)

As @gerardkd mentioned **this should only be added to your local config!**

- [http://getkirby.com/docs/advanced/routing](http://getkirby.com/docs/advanced/routing)
- [http://getkirby.com/docs/cheatsheet/user/login](http://getkirby.com/docs/cheatsheet/user/login)

---

<div class="post-metadata">

**Author:** ![lukasbestle](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/lukasbestle/32/11437_2.png) [@lukasbestle](https://forum.getkirby.com/u/lukasbestle)\
**Post date:** [January 12, 2016, 10:31am UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/6 "2016-01-12T10:31:07Z")

</div>

I have added a check to your code that only logs the user in on `localhost` to make sure. 🙂

---

<div class="post-metadata">

**Author:** ![jenstornell](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/jenstornell/32/546_2.png) [@jenstornell](https://forum.getkirby.com/u/jenstornell)\
**Post date:** [January 12, 2016, 12:21pm UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/7 "2016-01-12T12:21:12Z")

</div>

How awesome is that! You are my hero of the day! 🙂

---

<div class="post-metadata">

**Author:** ![jenstornell](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/jenstornell/32/546_2.png) [@jenstornell](https://forum.getkirby.com/u/jenstornell)\
**Post date:** [January 12, 2016, 12:33pm UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/8 "2016-01-12T12:33:13Z")

</div>

## Plugin

### autologin.php

Add this code to `/site/plugins/autologin/autologin.php`.

```php
<?php
autologin();

function autologin() {
  // Prevent access on the production system
  if(url::host() !== c::get('autologin.host', 'localhost')) return false;

  // Add route if localhost environment
  kirby()->routes(array(
    array(
      'pattern' => c::get('autologin.route', 'autologin'),
      'action' => function() {
        $user = site()->user( c::get('autologin.username') );
        if($user and $user->login( c::get('autologin.password') ) ) {
          go( c::get('autologin.redirect', 'panel') );
        } else {
          echo 'Invalid username or password';
          return false;
        }
      }
    )
  ));
}

```

### config.php

Add this to your `config.php`.

```php
c::set('autologin.username', 'your-username');
c::set('autologin.password', 'your-password');
c::set('autologin.redirect', 'site'); // Defaults to "panel"
c::set('autologin.route', 'slug'); // Defaults to "autologin"
c::set('autologin.host', 'host'); // Defaults to "localhost"

```

---

<div class="post-metadata">

**Author:** ![lukasbestle](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/lukasbestle/32/11437_2.png) [@lukasbestle](https://forum.getkirby.com/u/lukasbestle)\
**Post date:** [January 12, 2016, 12:49pm UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/9 "2016-01-12T12:49:49Z")

</div>

Looks great! Just a little improvement you could make:

The `c::get()` function accepts a default value, so you can use the following to make it even more flexible:

```php
go(c::get('autologin.redirect', 'panel'));

```

The config value could then be set to any page URI or not defined to be set to `panel`.

---

<div class="post-metadata">

**Author:** ![jenstornell](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/jenstornell/32/546_2.png) [@jenstornell](https://forum.getkirby.com/u/jenstornell)\
**Post date:** [January 12, 2016, 12:57pm UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/10 "2016-01-12T12:57:01Z")

</div>

Thanks! Yes, I knew about it. Was in a hurry to get it out, I guess. Updated the code.

### Custom route option added

I also added to option to add a custom route if “autologin” is not the prefered slug to use.

---

<div class="post-metadata">

**Author:** ![gerardkd](https://avatars.discourse-cdn.com/v4/letter/g/e56c9b/32.png) [@gerardkd](https://forum.getkirby.com/u/gerardkd)\
**Post date:** [January 12, 2016, 1:55pm UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/11 "2016-01-12T13:55:06Z")

</div>

If you use custom hosts with Mamp or something, like ‘myproject.dev’, the if-check will always return false. If you set that as a option as well, it’s totally flexible for your dev-environment needs 🙂

---

<div class="post-metadata">

**Author:** ![jenstornell](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/jenstornell/32/546_2.png) [@jenstornell](https://forum.getkirby.com/u/jenstornell)\
**Post date:** [January 12, 2016, 2:49pm UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/12 "2016-01-12T14:49:52Z")

</div>

Agree! I added another option to the code. Thanks!

---

<div class="post-metadata">

**Author:** ![flokosiol](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/flokosiol/32/468_2.png) [@flokosiol](https://forum.getkirby.com/u/flokosiol)\
**Post date:** [January 12, 2016, 3:12pm UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/13 "2016-01-12T15:12:30Z")

</div>

That was great teamwork!  
@jenstornell, @gerardkd, @lukasbestle  
😄

---

<div class="post-metadata">

**Author:** ![jenstornell](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/jenstornell/32/546_2.png) [@jenstornell](https://forum.getkirby.com/u/jenstornell)\
**Post date:** [January 14, 2016, 9:15am UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/14 "2016-01-14T09:15:03Z")

</div>

Would it be ok if I add the plugin (that is much based on your code) and put it on Github? I have some ideas on more development on this thing.

I will try to add stuff to make it possible to have an autologin on a live site as well. I know it can be really dangerous with just a link to login but with some extra protection layers I hope it might work.

---

<div class="post-metadata">

**Author:** ![flokosiol](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/flokosiol/32/468_2.png) [@flokosiol](https://forum.getkirby.com/u/flokosiol)\
**Post date:** [January 14, 2016, 10:29am UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/15 "2016-01-14T10:29:49Z")

</div>

Ok, no problem. Maybe you can mention me/us 😉

---

<div class="post-metadata">

**Author:** ![jenstornell](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/jenstornell/32/546_2.png) [@jenstornell](https://forum.getkirby.com/u/jenstornell)\
**Post date:** [January 14, 2016, 12:16pm UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/16 "2016-01-14T12:16:05Z")

</div>

Sure, thanks! 🙂

I don’t have a schedule for it yet so don’t sit up and wait (I’m working on my [Splitview](https://github.com/jenstornell/splitview) plugin right now).

---

<div class="post-metadata">

**Author:** ![jenstornell](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/jenstornell/32/546_2.png) [@jenstornell](https://forum.getkirby.com/u/jenstornell)\
**Post date:** [October 30, 2017, 1:52pm UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/17 "2017-10-30T13:52:48Z")

</div>

…and now it has evolved into a plugin…

**Github:** [https://github.com/jenstornell/kirby-autologin](https://github.com/jenstornell/kirby-autologin)

---

<div class="post-metadata">

**Author:** ![distantnative](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.getkirby.com/distantnative/32/11319_2.png) [@distantnative](https://forum.getkirby.com/u/distantnative)\
**Post date:** [February 6, 2025, 5:31pm UTC](https://forum.getkirby.com/t/bypass-login-for-localhost-environment/3015/18 "2025-02-06T17:31:49Z")

</div>


