LoVisual/backend/addons-registry/README.md
loki5512344 c57f851a8b
feat(accounts): outgoing mail over SMTP (Resend), email verification, fail-closed password reset
- mail/ module (lettre, ru/en templates), links built only from PUBLIC_BASE_URL
- migration 0006: accounts.email_verified_at, shared email_tokens table (verify + reset), existing accounts marked verified
- reset mailer no longer logs tokens; RESET_MAIL_MODE=log is dev-only and refused with COOKIE_SECURE=true; Disabled by default answers 503
- forgot-password and resend-verification do their work in a background task (no timing oracle)
- device linking requires a verified email; email_verified exposed via /me and gRPC
- gateway rate limits, SMTP_* in compose and .env.example
- frontend: verify, forgot-password, reset-password pages, verify banner, ru/en strings
2026-10-09 21:08:33 +02:00

20 lines
973 B
Markdown

# addons-registry (planned)
Addon marketplace backend: versions, publishing, moderation (Подсистема 3).
See `TODO.md` (Фаза 10, "Подсистема 3") and `backend/STRUCTURE.md`. No
implementation plan yet.
## Publish gate (decided, applies when this service is built)
Publishing addons is allowed only for accounts with a **verified email**.
There is no `can_publish_addons` HTTP endpoint to call: the check lives in
the caller, and the data comes from accounts-service:
- `AuthenticateDeviceReply.email_verified` (gRPC, `common/proto/accounts.proto`)
— returned alongside `account_id` since the 0006 migration. For
site-session flows (publishing from the site), call the accounts-service
`/me`-equivalent or extend the internal gRPC with an account lookup; do
not re-derive verification state locally.
- Rule: `email_verified == false` → publish endpoints answer `403 Forbidden`
with `email not verified`, mirroring `/device/confirm`.