Add remember-me and OTP autofill, fix session persistence
Sign-in gains a "Keep me signed in" checkbox: checked issues a 30-day token and prefills the address next launch, unchecked drops the session to 12 hours and forgets the address. The TTL is chosen server-side in the login route. Emailed codes are now reachable without retyping. OtpField opts into the iOS one-time-code keyboard suggestion and raises a paste chip when the user returns from Gmail with a code on the clipboard. The mails put the code first in the subject and body, which is what makes Gmail render its "Copy code" notification action at all. Fixes found along the way: - Session was wiped on every launch. decodeJwtExp used atob, which neither RN 0.74 nor Expo SDK 51 defines, so it threw, returned null, and the caller read that as "expired" and deleted the token. Replaced with a dependency-free base64url decoder, and restore now only discards a session it can prove is expired. - Verification and reset codes counted attempts but never enforced them, leaving a 6-digit code open to unlimited guessing. Both routes now charge the attempt before comparing so concurrent guesses can't race past the cap of five, and compare in constant time. - A wrong verification code showed the "Verified" success screen: onModalHide fired unconditionally, so the failure state advanced the flow. Only an explicit "verified" state does that now. - fetchAPI discarded the server's error body, so the UI substring-matched synthetic status strings and showed "Could not sign in" for everything. It now throws ApiError carrying status and the server's message. - Login answered a missing account faster than a wrong password; it now runs the same scrypt work either way. - Blank email or password is caught client-side instead of surfacing as an opaque 400, and a failed attempt only clears the password on a 401. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
eceb6b45d5
commit
bc23c94ea2
@@ -1,12 +1,8 @@
|
||||
import { createHash } from "crypto";
|
||||
|
||||
import { sql } from "@/lib/db";
|
||||
import { MAX_CODE_ATTEMPTS, codeMatches } from "@/lib/otp";
|
||||
import { hashPassword } from "@/lib/password";
|
||||
import { issueSession, toProfile } from "@/lib/users";
|
||||
|
||||
const hashCode = (email: string, code: string): string =>
|
||||
createHash("sha256").update(`${email}:${code}`).digest("hex");
|
||||
|
||||
export async function POST(req: Request) {
|
||||
const { email, code, password } = await req.json();
|
||||
|
||||
@@ -27,19 +23,22 @@ export async function POST(req: Request) {
|
||||
const normalized = email.trim().toLowerCase();
|
||||
|
||||
try {
|
||||
const valid = await sql<{ email: string }>`
|
||||
SELECT email FROM password_reset_codes
|
||||
WHERE email = ${normalized}
|
||||
AND code_hash = ${hashCode(normalized, code)}
|
||||
AND expires_at > CURRENT_TIMESTAMP
|
||||
// Charge the attempt before comparing so concurrent guesses can't race
|
||||
// past the cap, and so a correct guess still costs one of the five.
|
||||
const attempts = await sql<{ code_hash: string; attempts: number }>`
|
||||
UPDATE password_reset_codes
|
||||
SET attempts = attempts + 1
|
||||
WHERE email = ${normalized} AND expires_at > CURRENT_TIMESTAMP
|
||||
RETURNING code_hash, attempts
|
||||
`;
|
||||
|
||||
if (!valid[0]) {
|
||||
await sql`
|
||||
UPDATE password_reset_codes SET attempts = attempts + 1
|
||||
WHERE email = ${normalized}
|
||||
`;
|
||||
const record = attempts[0];
|
||||
|
||||
if (
|
||||
!record ||
|
||||
record.attempts > MAX_CODE_ATTEMPTS ||
|
||||
!codeMatches(record.code_hash, normalized, code)
|
||||
) {
|
||||
return Response.json(
|
||||
{ error: "Invalid or expired reset code." },
|
||||
{ status: 400 },
|
||||
|
||||
Reference in New Issue
Block a user