Install BoxLang, clone the template, run migrations, and be looking at the login screen in under ten minutes.
Application code lives in app/, fully separated from the public webroot in public/ — enhanced security by default.
Session auth via cbauth, @secured handler annotations, CSRF rotation, JWT support, IP-based rate limiting, and a resource:action permission model.
WebAuthn passkey enrollment, optional required-enrollment gating, and profile tools to list and remove credentials.
Per-user preferences persist with the account and can be updated from the profile or managed from the admin user detail view.
Google OAuth is the shipped example; cbSSO can register additional providers, with account linking and provisioning governed by cbGenesis.
Configure named cbfs disks with the storage providers your app needs. This template uses a private local assets disk for user avatars and branding-logo uploads.
bx-image crops and resizes avatar and logo uploads into small and large variants, ready to serve at the size each UI needs.
Token-based account emails use cbmailservices, with file delivery in development and configurable production mail protocols such as SMTP, Postmark, or SendGrid.
BaseEntity/BaseService conventions on top of bx-orm,
migrations, and qb for anything raw SQL does better.
Server-rendered BXM views, sprinkled with small Alpine components, compiled by Vite with hot module reload.
TestBox unit specs for every entity and service, plus integration specs that exercise real HTTP requests.
Environment variables for the essentials, DB-backed admin settings for everything else — no redeploy needed to change them.
A real go-live checklist, Docker support, and a choice of CommandBox or the BoxLang MiniServer.
Invite users, manage account status, assign roles and permissions, and administer tokens and profile settings from the admin panel.
Automatically record sign-ins, sign-outs, and access failures; filter and inspect activity, export CSV, and manage log retention.