Improved login and prepared logout

Change-Id: I29e7c3752682e1016cbbd861ac1c1c3dd64964ab
diff --git a/templates/layouts/main.html.ep b/templates/layouts/main.html.ep
index 519229e..7ddb283 100644
--- a/templates/layouts/main.html.ep
+++ b/templates/layouts/main.html.ep
@@ -37,10 +37,10 @@
       <button type="submit"><span><%= loc 'go' %></span></button>
     </div>
   % end
-  <ul>
-    <li><%= link_to loc('register') => 'register' %></li>
-    <li><%= link_to loc('pwdforgotten') => 'pwd_forgotten' %></li>
-  </ul>
+%#  <ul>
+%#    <li><%= link_to loc('register') => 'register' %></li>
+%#    <li><%= link_to loc('pwdforgotten') => 'pwd_forgotten' %></li>
+%#  </ul>
 </fieldset>
 % end
 % }
diff --git a/templates/partial/header.html.ep b/templates/partial/header.html.ep
index fdc25d6..a81aebc 100644
--- a/templates/partial/header.html.ep
+++ b/templates/partial/header.html.ep
@@ -1,11 +1,14 @@
 <header>
   <%= link_to 'index', class => 'logo', begin %><h1><span><%= title() // loc('korap_desc') %></span></h1><% end %>
   <div class="button top">
-<!--
-    <a href="#"
-       class="login"
-       title="<%= loc 'login' %>"><span><%= loc 'login' %></span></a>
--->
+
+% if (stash('user')) {
+   %# TODO: CSRF protection
+   <a href="<%= url_for 'logout' %>"
+      class="logout"
+      title="<%= loc 'logout' %>: <%= stash('user') %>"><span><%= loc 'logout' %></span></a>
+% };
+
   </div>
   <form autocomplete="off" action="<%= url_for 'index' %>" id="searchform">
     <div id="searchbar">