feat(accounts): outgoing mail over SMTP (Resend), email verification, fail-closed password reset
- mail/ module (lettre, ru/en templates), links built only from PUBLIC_BASE_URL - migration 0006: accounts.email_verified_at, shared email_tokens table (verify + reset), existing accounts marked verified - reset mailer no longer logs tokens; RESET_MAIL_MODE=log is dev-only and refused with COOKIE_SECURE=true; Disabled by default answers 503 - forgot-password and resend-verification do their work in a background task (no timing oracle) - device linking requires a verified email; email_verified exposed via /me and gRPC - gateway rate limits, SMTP_* in compose and .env.example - frontend: verify, forgot-password, reset-password pages, verify banner, ru/en strings
This commit is contained in:
parent
12ce6216b6
commit
c57f851a8b
48 changed files with 1810 additions and 120 deletions
|
|
@ -6,6 +6,9 @@ package accounts.v1;
|
|||
service AccountsInternal {
|
||||
// Resolves a mod's long-lived device token to its account and bumps
|
||||
// device_links.last_seen. UNAUTHENTICATED if the token is unknown/revoked.
|
||||
// email_verified lets capability-gating callers (addons-registry publish,
|
||||
// future mod features) refuse service to unconfirmed addresses without a
|
||||
// second lookup.
|
||||
rpc AuthenticateDevice(AuthenticateDeviceRequest) returns (AuthenticateDeviceReply);
|
||||
|
||||
// Nick + avatar for showcase authors etc. Never returns email or role.
|
||||
|
|
@ -13,7 +16,10 @@ service AccountsInternal {
|
|||
}
|
||||
|
||||
message AuthenticateDeviceRequest { string device_token = 1; }
|
||||
message AuthenticateDeviceReply { string account_id = 1; }
|
||||
message AuthenticateDeviceReply {
|
||||
string account_id = 1;
|
||||
bool email_verified = 2;
|
||||
}
|
||||
|
||||
message GetPublicProfilesRequest { repeated string account_ids = 1; }
|
||||
message PublicProfile {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue