Make the magic-link resend cooldown configurable

EmailVerifier::RESEND_INTERVAL_SECONDS was a hardcoded class constant
shared (via a copy-of-a-constant) by AuthController and
EmailVerificationController. It's now a constructor param
(resendIntervalSeconds, default 60, same as before) sourced from
Config -- new MAGIC_LINK_RESEND_SECONDS env var, default unchanged.

Docker Compose sets it to 0, so magic links resend immediately during
local development instead of waiting out the throttle.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-04 21:30:41 +01:00
co-authored by Claude Sonnet 5
parent 4a9717caa5
commit 91c0e8d6af
9 changed files with 31 additions and 7 deletions
+1 -1
View File
@@ -83,6 +83,6 @@ final class AuthController extends Controller
$lastSent = $user['verification_email_sent_at'] ?? null;
return $lastSent !== null
&& (time() - (int) strtotime($lastSent)) < EmailVerifier::RESEND_INTERVAL_SECONDS;
&& (time() - (int) strtotime($lastSent)) < $this->verifier->resendIntervalSeconds;
}
}
@@ -16,7 +16,6 @@ use Psr\Http\Message\ServerRequestInterface as Request;
final class EmailVerificationController extends Controller
{
private const RESEND_INTERVAL_SECONDS = EmailVerifier::RESEND_INTERVAL_SECONDS;
private const EMAIL_MAX = 255;
public function __construct(
@@ -115,7 +114,7 @@ final class EmailVerificationController extends Controller
return $this->json($response, [
'message' => 'Confirmation email sent to the new address.',
'pending_email' => $newEmail,
'retry_after' => self::RESEND_INTERVAL_SECONDS,
'retry_after' => $this->verifier->resendIntervalSeconds,
], 202);
}
@@ -130,11 +129,11 @@ final class EmailVerificationController extends Controller
}
$elapsed = time() - (int) strtotime($lastSent);
if ($elapsed < self::RESEND_INTERVAL_SECONDS) {
if ($elapsed < $this->verifier->resendIntervalSeconds) {
throw new ApiException(
'Please wait a moment before requesting another email.',
429,
['retry_after' => self::RESEND_INTERVAL_SECONDS - $elapsed],
['retry_after' => $this->verifier->resendIntervalSeconds - $elapsed],
);
}
}