LoVisual/backend/common/proto/accounts.proto
loki5512344 c57f851a8b
feat(accounts): outgoing mail over SMTP (Resend), email verification, fail-closed password reset
- mail/ module (lettre, ru/en templates), links built only from PUBLIC_BASE_URL
- migration 0006: accounts.email_verified_at, shared email_tokens table (verify + reset), existing accounts marked verified
- reset mailer no longer logs tokens; RESET_MAIL_MODE=log is dev-only and refused with COOKIE_SECURE=true; Disabled by default answers 503
- forgot-password and resend-verification do their work in a background task (no timing oracle)
- device linking requires a verified email; email_verified exposed via /me and gRPC
- gateway rate limits, SMTP_* in compose and .env.example
- frontend: verify, forgot-password, reset-password pages, verify banner, ru/en strings
2026-10-09 21:08:33 +02:00

30 lines
1.2 KiB
Protocol Buffer

syntax = "proto3";
package accounts.v1;
// Internal-only API of accounts-service. Never exposed publicly; every call
// must carry the x-lovisual-internal-key metadata entry.
service AccountsInternal {
// Resolves a mod's long-lived device token to its account and bumps
// device_links.last_seen. UNAUTHENTICATED if the token is unknown/revoked.
// email_verified lets capability-gating callers (addons-registry publish,
// future mod features) refuse service to unconfirmed addresses without a
// second lookup.
rpc AuthenticateDevice(AuthenticateDeviceRequest) returns (AuthenticateDeviceReply);
// Nick + avatar for showcase authors etc. Never returns email or role.
rpc GetPublicProfiles(GetPublicProfilesRequest) returns (GetPublicProfilesReply);
}
message AuthenticateDeviceRequest { string device_token = 1; }
message AuthenticateDeviceReply {
string account_id = 1;
bool email_verified = 2;
}
message GetPublicProfilesRequest { repeated string account_ids = 1; }
message PublicProfile {
string account_id = 1;
string display_nick = 2;
string avatar_url = 3; // empty string when the account has no avatar
}
message GetPublicProfilesReply { repeated PublicProfile profiles = 1; }