Portal profile section with verified email change #148

Stängd
öppnade 2026-08-02 08:06:29 +00:00 av supernaut · 1 kommentar
Ägare

Make the portal the one place a user edits their name and email.

Epic: bitborg-docs#64

Scope

  • Replace the read-only identity card with an editable profile section. The card
    rendered from the login token, so a change made anywhere else stayed invisible
    until the user signed out and back in — a stale copy of data the page did not
    own.
  • Display name writes straight through, with the session re-minted so the panel
    reflects it immediately.
  • Email changes through a confirmation loop, because the identity provider has no
    mail sender and cannot verify an address.
  • Present the username as fixed, with an explanation.
  • Retarget the outward links at the exact pages that own what is not here, rather
    than at front doors.

Email change — the part that needs review

This is also the account-recovery address, so: the link goes only to the proposed
address; only the token's hash is stored; requests are single-use, expire in two
hours, and supersede any still open; the token is consumed before the write, so a
successful change cannot leave a usable token behind; unknown, spent, expired and
wrong-account tokens all return one indistinguishable answer; confirming needs
the session as well as the token; and the previous address is notified
afterwards, which is the detection path if a session is ever stolen.

Sending is rate-limited — without a cap, an authenticated account is a free relay
for mailing arbitrary addresses.

Notes

  • Adds a migration for the pending-changes table; it runs at container start on
    deploy.
  • Guide and FAQ updated in both languages, with Swedish domain terms taken from
    Forgejo's locale.

Status

Open in PR #147.

Make the portal the one place a user edits their name and email. Epic: bitborg-docs#64 ## Scope - Replace the read-only identity card with an editable profile section. The card rendered from the login token, so a change made anywhere else stayed invisible until the user signed out and back in — a stale copy of data the page did not own. - Display name writes straight through, with the session re-minted so the panel reflects it immediately. - Email changes through a confirmation loop, because the identity provider has no mail sender and cannot verify an address. - Present the username as fixed, with an explanation. - Retarget the outward links at the exact pages that own what is not here, rather than at front doors. ## Email change — the part that needs review This is also the account-recovery address, so: the link goes only to the proposed address; only the token's hash is stored; requests are single-use, expire in two hours, and supersede any still open; the token is consumed before the write, so a successful change cannot leave a usable token behind; unknown, spent, expired and wrong-account tokens all return one indistinguishable answer; confirming needs the session as well as the token; and the previous address is notified afterwards, which is the detection path if a session is ever stolen. Sending is rate-limited — without a cap, an authenticated account is a free relay for mailing arbitrary addresses. ## Notes - Adds a migration for the pending-changes table; it runs at container start on deploy. - Guide and FAQ updated in both languages, with Swedish domain terms taken from Forgejo's locale. ## Status Open in PR #147.
Upphovsperson
Ägare

Delivered in PR #147, deployed and verified as far as is possible without a session.

Verified: CI and image build succeeded, the container rebuilt from the new image, migration 0005 created email_change_requests, the site serves, and /account correctly gates to SSO (302 → /auth/login?return_to=%2Faccount).

NOT yet exercised by a human — worth a smoke test:

  • change the display name and confirm the panel updates immediately (the session re-mint) and the Git account follows within one reconcile cycle;
  • request an email change and confirm the link arrives at the NEW address only, that nothing changes until it is opened, and that the previous address is notified afterwards;
  • confirm a reused or expired link is rejected.
Delivered in PR #147, deployed and verified as far as is possible without a session. Verified: CI and image build succeeded, the container rebuilt from the new image, migration 0005 created `email_change_requests`, the site serves, and `/account` correctly gates to SSO (302 → /auth/login?return_to=%2Faccount). NOT yet exercised by a human — worth a smoke test: - change the display name and confirm the panel updates immediately (the session re-mint) and the Git account follows within one reconcile cycle; - request an email change and confirm the link arrives at the NEW address only, that nothing changes until it is opened, and that the previous address is notified afterwards; - confirm a reused or expired link is rejected.
supernaut lade till detta till projektet Bitborg Web 2026-08-02 10:10:31 +00:00
Logga in för att delta i denna konversation.
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-web#148
Ingen beskrivning angiven.