Accounts: email and password #37
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "feature/accounts"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #18. Step 2 of the plan: simple accounts, email address and password only, no emails and no SSO (owner decision).
Reader pages (plain forms, work without JavaScript)
/signup: email, password twice (8+ characters)/signin: returns to the page the reader came from (?next=, same-site paths only)/account: sign out, change password (signs out other devices), delete account (password required; removes the account and its data)Security
scrypt$N$r$p$salt$hashso the cost can be raised later; unknown emails take as long as wrong passwords.SITE_HOSTS(build time, default127.0.0.1,localhost). The production domain must be added at deploy, or sign-in forms get 403.Database:
users,sessions(indb/schema.sql, applied by the import orpsql < db/schema.sql).Tested
npm test: 19 pass, including the HTTP flow (sign-up, duplicate email, sign-in, wrong password, change password signs out other sessions, sign-out, delete) and the per-email rate limit.?next=works and//evil.exampleis ignored; deleting the account leaves no rows.Independent of #26 (selection menu); either can merge first.
🤖 Generated with Claude Code