- mail/ module (lettre, ru/en templates), links built only from PUBLIC_BASE_URL - migration 0006: accounts.email_verified_at, shared email_tokens table (verify + reset), existing accounts marked verified - reset mailer no longer logs tokens; RESET_MAIL_MODE=log is dev-only and refused with COOKIE_SECURE=true; Disabled by default answers 503 - forgot-password and resend-verification do their work in a background task (no timing oracle) - device linking requires a verified email; email_verified exposed via /me and gRPC - gateway rate limits, SMTP_* in compose and .env.example - frontend: verify, forgot-password, reset-password pages, verify banner, ru/en strings |
||
|---|---|---|
| .. | ||
| README.md | ||
addons-registry (planned)
Addon marketplace backend: versions, publishing, moderation (Подсистема 3).
See TODO.md (Фаза 10, "Подсистема 3") and backend/STRUCTURE.md. No
implementation plan yet.
Publish gate (decided, applies when this service is built)
Publishing addons is allowed only for accounts with a verified email.
There is no can_publish_addons HTTP endpoint to call: the check lives in
the caller, and the data comes from accounts-service:
AuthenticateDeviceReply.email_verified(gRPC,common/proto/accounts.proto) — returned alongsideaccount_idsince the 0006 migration. For site-session flows (publishing from the site), call the accounts-service/me-equivalent or extend the internal gRPC with an account lookup; do not re-derive verification state locally.- Rule:
email_verified == false→ publish endpoints answer403 Forbiddenwithemail not verified, mirroring/device/confirm.