Add stage 8: passwordless magic-link login
Backend
- POST /api/auth/magic-link (public): emails a one-time login link for an
address. Always 202 with the same body so accounts can't be enumerated; a
link is sent only when the account exists and wasn't emailed in the last
60s. Opening it (existing verify-email endpoint) returns a session and, as a
side effect, verifies the address. New EmailVerifier::sendLoginLink; the
60s interval is now EmailVerifier::RESEND_INTERVAL_SECONDS, shared.
Frontend
- LoginView defaults to magic-link mode: email only, "Log in with email". A
"Log in with password" link reveals the password field, changes the button
to "Log in", and itself becomes "Get a magic link" to switch back.
- VerifyEmailView copy is now login-neutral ("Signing you in").
Tests: 5 new (magic-link login, implicit verification, enumeration-safety,
throttle, validation). Suite: 37 passing.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
+11
-5
@@ -61,8 +61,8 @@ server response replaces local state.
|
||||
|
||||
## Auth flow
|
||||
|
||||
- The token from `POST /api/auth/register` or `/login` is kept in `localStorage`
|
||||
and sent as `Authorization: Bearer …`.
|
||||
- The token from register / login / opening a magic link is kept in
|
||||
`localStorage` and sent as `Authorization: Bearer …`.
|
||||
- On load, `fetchMe()` validates the stored token via `GET /api/me`; a failure
|
||||
clears it.
|
||||
- Routes with `meta.requiresAuth` redirect to `/login` (preserving the intended
|
||||
@@ -70,12 +70,18 @@ server response replaces local state.
|
||||
- Registration signs the user in immediately; the new account's email is
|
||||
unverified (`user.email_verified === false`). The header shows a "verify
|
||||
email" badge linking to `/profile`.
|
||||
- `LoginView` defaults to **magic link**: an email field and a "Log in with
|
||||
email" button that calls `POST /api/auth/magic-link`. A "Log in with password"
|
||||
link reveals the password field and switches the button to a plain "Log in"
|
||||
(`POST /api/auth/login`); the link then reads "Get a magic link" to switch
|
||||
back.
|
||||
|
||||
## Email verification & profile
|
||||
|
||||
- The registration email links to `/verify-email?token=…`. `VerifyEmailView`
|
||||
POSTs the token to the API, which returns a session — so opening the link both
|
||||
verifies the address and signs the user in — then redirects to the lists.
|
||||
- `/verify-email?token=…` is the target for every magic link (verification,
|
||||
passwordless login, email change). `VerifyEmailView` POSTs the token to the
|
||||
API, which returns a session — so opening any link both verifies the address
|
||||
and signs the user in — then redirects to the lists.
|
||||
- `/profile` (`ProfileView`) shows the address and verification status. When
|
||||
unverified it offers a **Resend** button; the API throttles to once a minute,
|
||||
and the button shows a live countdown (driven by `retry_after`, and by `429`
|
||||
|
||||
Reference in New Issue
Block a user