Portal profile section with verified email change #148
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web#148
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Make the portal the one place a user edits their name and email.
Epic: bitborg-docs#64
Scope
rendered from the login token, so a change made anywhere else stayed invisible
until the user signed out and back in — a stale copy of data the page did not
own.
reflects it immediately.
mail sender and cannot verify an address.
than at front doors.
Email change — the part that needs review
This is also the account-recovery address, so: the link goes only to the proposed
address; only the token's hash is stored; requests are single-use, expire in two
hours, and supersede any still open; the token is consumed before the write, so a
successful change cannot leave a usable token behind; unknown, spent, expired and
wrong-account tokens all return one indistinguishable answer; confirming needs
the session as well as the token; and the previous address is notified
afterwards, which is the detection path if a session is ever stolen.
Sending is rate-limited — without a cap, an authenticated account is a free relay
for mailing arbitrary addresses.
Notes
deploy.
Forgejo's locale.
Status
Open in PR #147.
Delivered in PR #147, deployed and verified as far as is possible without a session.
Verified: CI and image build succeeded, the container rebuilt from the new image, migration 0005 created
email_change_requests, the site serves, and/accountcorrectly gates to SSO (302 → /auth/login?return_to=%2Faccount).NOT yet exercised by a human — worth a smoke test: