- mail/ module (lettre, ru/en templates), links built only from PUBLIC_BASE_URL - migration 0006: accounts.email_verified_at, shared email_tokens table (verify + reset), existing accounts marked verified - reset mailer no longer logs tokens; RESET_MAIL_MODE=log is dev-only and refused with COOKIE_SECURE=true; Disabled by default answers 503 - forgot-password and resend-verification do their work in a background task (no timing oracle) - device linking requires a verified email; email_verified exposed via /me and gRPC - gateway rate limits, SMTP_* in compose and .env.example - frontend: verify, forgot-password, reset-password pages, verify banner, ru/en strings
30 lines
1.2 KiB
Protocol Buffer
30 lines
1.2 KiB
Protocol Buffer
syntax = "proto3";
|
|
package accounts.v1;
|
|
|
|
// Internal-only API of accounts-service. Never exposed publicly; every call
|
|
// must carry the x-lovisual-internal-key metadata entry.
|
|
service AccountsInternal {
|
|
// Resolves a mod's long-lived device token to its account and bumps
|
|
// device_links.last_seen. UNAUTHENTICATED if the token is unknown/revoked.
|
|
// email_verified lets capability-gating callers (addons-registry publish,
|
|
// future mod features) refuse service to unconfirmed addresses without a
|
|
// second lookup.
|
|
rpc AuthenticateDevice(AuthenticateDeviceRequest) returns (AuthenticateDeviceReply);
|
|
|
|
// Nick + avatar for showcase authors etc. Never returns email or role.
|
|
rpc GetPublicProfiles(GetPublicProfilesRequest) returns (GetPublicProfilesReply);
|
|
}
|
|
|
|
message AuthenticateDeviceRequest { string device_token = 1; }
|
|
message AuthenticateDeviceReply {
|
|
string account_id = 1;
|
|
bool email_verified = 2;
|
|
}
|
|
|
|
message GetPublicProfilesRequest { repeated string account_ids = 1; }
|
|
message PublicProfile {
|
|
string account_id = 1;
|
|
string display_nick = 2;
|
|
string avatar_url = 3; // empty string when the account has no avatar
|
|
}
|
|
message GetPublicProfilesReply { repeated PublicProfile profiles = 1; }
|