Add stage 8: passwordless magic-link login
Backend
- POST /api/auth/magic-link (public): emails a one-time login link for an
address. Always 202 with the same body so accounts can't be enumerated; a
link is sent only when the account exists and wasn't emailed in the last
60s. Opening it (existing verify-email endpoint) returns a session and, as a
side effect, verifies the address. New EmailVerifier::sendLoginLink; the
60s interval is now EmailVerifier::RESEND_INTERVAL_SECONDS, shared.
Frontend
- LoginView defaults to magic-link mode: email only, "Log in with email". A
"Log in with password" link reveals the password field, changes the button
to "Log in", and itself becomes "Get a magic link" to switch back.
- VerifyEmailView copy is now login-neutral ("Signing you in").
Tests: 5 new (magic-link login, implicit verification, enumeration-safety,
throttle, validation). Suite: 37 passing.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -96,6 +96,64 @@ final class EmailVerificationTest extends ApiTestCase
|
||||
self::assertSame(409, $response->getStatusCode());
|
||||
}
|
||||
|
||||
public function test_magic_link_login_emails_a_link_that_signs_the_user_in(): void
|
||||
{
|
||||
$this->request('POST', '/api/auth/register', ['email' => 'ada@example.com', 'password' => 'password123']);
|
||||
$this->cooldownElapsed('ada@example.com');
|
||||
|
||||
$requested = $this->request('POST', '/api/auth/magic-link', ['email' => 'ADA@example.com']);
|
||||
self::assertSame(202, $requested->getStatusCode());
|
||||
|
||||
$login = $this->lastEmail();
|
||||
self::assertSame('ada@example.com', $login['to']);
|
||||
self::assertSame('Your login link', $login['subject']);
|
||||
|
||||
$session = $this->request('POST', '/api/auth/verify-email', ['token' => $this->tokenFromEmail($login)]);
|
||||
self::assertSame(200, $session->getStatusCode());
|
||||
$body = $this->decode($session);
|
||||
self::assertSame('ada@example.com', $body['user']['email']);
|
||||
self::assertTrue($body['user']['email_verified']);
|
||||
self::assertNotEmpty($body['token']);
|
||||
}
|
||||
|
||||
public function test_magic_link_login_verifies_an_unverified_account(): void
|
||||
{
|
||||
$this->request('POST', '/api/auth/register', ['email' => 'ada@example.com', 'password' => 'password123']);
|
||||
$this->cooldownElapsed('ada@example.com');
|
||||
|
||||
$this->request('POST', '/api/auth/magic-link', ['email' => 'ada@example.com']);
|
||||
$body = $this->decode(
|
||||
$this->request('POST', '/api/auth/verify-email', ['token' => $this->tokenFromEmail()]),
|
||||
);
|
||||
|
||||
self::assertTrue($body['user']['email_verified']);
|
||||
}
|
||||
|
||||
public function test_magic_link_login_is_silent_for_an_unknown_address(): void
|
||||
{
|
||||
$response = $this->request('POST', '/api/auth/magic-link', ['email' => 'nobody@example.com']);
|
||||
|
||||
self::assertSame(202, $response->getStatusCode());
|
||||
self::assertSame([], $this->sentEmails());
|
||||
}
|
||||
|
||||
public function test_magic_link_login_does_not_resend_within_the_interval(): void
|
||||
{
|
||||
// Registration already sent a verification email moments ago.
|
||||
$this->request('POST', '/api/auth/register', ['email' => 'ada@example.com', 'password' => 'password123']);
|
||||
|
||||
$response = $this->request('POST', '/api/auth/magic-link', ['email' => 'ada@example.com']);
|
||||
|
||||
self::assertSame(202, $response->getStatusCode());
|
||||
self::assertCount(1, $this->sentEmails()); // still just the registration email
|
||||
}
|
||||
|
||||
public function test_magic_link_login_validates_the_address(): void
|
||||
{
|
||||
$response = $this->request('POST', '/api/auth/magic-link', ['email' => 'not-an-email']);
|
||||
self::assertSame(422, $response->getStatusCode());
|
||||
}
|
||||
|
||||
public function test_email_change_is_deferred_until_the_new_address_is_confirmed(): void
|
||||
{
|
||||
$auth = $this->authHeader('old@example.com');
|
||||
|
||||
Reference in New Issue
Block a user