Add stage 8: passwordless magic-link login

Backend
- POST /api/auth/magic-link (public): emails a one-time login link for an
  address. Always 202 with the same body so accounts can't be enumerated; a
  link is sent only when the account exists and wasn't emailed in the last
  60s. Opening it (existing verify-email endpoint) returns a session and, as a
  side effect, verifies the address. New EmailVerifier::sendLoginLink; the
  60s interval is now EmailVerifier::RESEND_INTERVAL_SECONDS, shared.

Frontend
- LoginView defaults to magic-link mode: email only, "Log in with email". A
  "Log in with password" link reveals the password field, changes the button
  to "Log in", and itself becomes "Get a magic link" to switch back.
- VerifyEmailView copy is now login-neutral ("Signing you in").

Tests: 5 new (magic-link login, implicit verification, enumeration-safety,
throttle, validation). Suite: 37 passing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-04 10:29:13 +01:00
co-authored by Claude Sonnet 5
parent 64ba21795b
commit be592f38fc
10 changed files with 195 additions and 21 deletions
+58
View File
@@ -96,6 +96,64 @@ final class EmailVerificationTest extends ApiTestCase
self::assertSame(409, $response->getStatusCode());
}
public function test_magic_link_login_emails_a_link_that_signs_the_user_in(): void
{
$this->request('POST', '/api/auth/register', ['email' => 'ada@example.com', 'password' => 'password123']);
$this->cooldownElapsed('ada@example.com');
$requested = $this->request('POST', '/api/auth/magic-link', ['email' => 'ADA@example.com']);
self::assertSame(202, $requested->getStatusCode());
$login = $this->lastEmail();
self::assertSame('ada@example.com', $login['to']);
self::assertSame('Your login link', $login['subject']);
$session = $this->request('POST', '/api/auth/verify-email', ['token' => $this->tokenFromEmail($login)]);
self::assertSame(200, $session->getStatusCode());
$body = $this->decode($session);
self::assertSame('ada@example.com', $body['user']['email']);
self::assertTrue($body['user']['email_verified']);
self::assertNotEmpty($body['token']);
}
public function test_magic_link_login_verifies_an_unverified_account(): void
{
$this->request('POST', '/api/auth/register', ['email' => 'ada@example.com', 'password' => 'password123']);
$this->cooldownElapsed('ada@example.com');
$this->request('POST', '/api/auth/magic-link', ['email' => 'ada@example.com']);
$body = $this->decode(
$this->request('POST', '/api/auth/verify-email', ['token' => $this->tokenFromEmail()]),
);
self::assertTrue($body['user']['email_verified']);
}
public function test_magic_link_login_is_silent_for_an_unknown_address(): void
{
$response = $this->request('POST', '/api/auth/magic-link', ['email' => 'nobody@example.com']);
self::assertSame(202, $response->getStatusCode());
self::assertSame([], $this->sentEmails());
}
public function test_magic_link_login_does_not_resend_within_the_interval(): void
{
// Registration already sent a verification email moments ago.
$this->request('POST', '/api/auth/register', ['email' => 'ada@example.com', 'password' => 'password123']);
$response = $this->request('POST', '/api/auth/magic-link', ['email' => 'ada@example.com']);
self::assertSame(202, $response->getStatusCode());
self::assertCount(1, $this->sentEmails()); // still just the registration email
}
public function test_magic_link_login_validates_the_address(): void
{
$response = $this->request('POST', '/api/auth/magic-link', ['email' => 'not-an-email']);
self::assertSame(422, $response->getStatusCode());
}
public function test_email_change_is_deferred_until_the_new_address_is_confirmed(): void
{
$auth = $this->authHeader('old@example.com');