feat(account): make the portal the single place to edit name and email #147
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!147
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/identity-profile-panel"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Turns the account panel from a read-only mirror into the one place a user edits
their name and email (ADR 0038).
Why the panel had to change
The panel rendered name and email from the
id_token, which is minted at login.So a change made anywhere else stayed invisible here until the user signed out
and back in — a stale copy of data the page did not own. Meanwhile the Git
application offered editable copies of both that propagated nowhere.
Display name
Written straight to Gitborg Auth, then projected onto the Git account. The
session cookie is re-minted on success so the panel reflects the new value
immediately rather than at next sign-in — the same pattern
/api/renovatealready uses, and for the same reason.
Empty is refused rather than passed through: an absent attribute is read
downstream as "unknown" and skipped, so an empty write would look accepted and
then quietly do nothing.
Email — the part worth the most review
Gitborg Auth has no mail sender, so it cannot verify an address. The portal owns
the confirmation loop instead. Since this is also the account-recovery address,
the flow is deliberately conservative:
proves control of the mailbox being moved to;
over working links;
any still open, so the address that sticks is the change most recently asked
for rather than whichever link was clicked last;
leave a usable token behind;
indistinguishable answer, so a stray link cannot be probed;
nothing for someone else;
a session is ever stolen, and the message says what it means and what to do.
Sending is rate-limited per client: without a cap, an authenticated account is a
free relay for mailing arbitrary addresses.
Username
Presented as fixed, with an explanation. It is the owner segment of every
repository URL the account holds, so changing it moves everything the user owns
and breaks links in workflows and documentation. Renaming is an operator action.
Signposting
The outward links now point at the exact pages that own what is not here —
sign-in and passkeys, SSH/GPG keys, access tokens — rather than at front doors.
Also
Both endpoints act on the session subject only, never a client-supplied
identity. Guide and FAQ updated in both languages; Swedish domain terms taken
from Forgejo's
sv-SElocale.Two things to know before merging
0005collides with the one onrefactor/sign-up(#146).Whichever merges second needs regenerating, and
src/db/schema.tswillconflict between the two branches.
request reports that it could not send rather than claiming success.
197 tests, lint, typecheck and build clean.