Skip to content

fix: reauthenticate only for sensitive settings changes - #53

Merged
darwin67 merged 3 commits into
mainfrom
fix/settings-reauthentication
Aug 21, 2026
Merged

darwin67 merged 3 commits into
mainfrom
fix/settings-reauthentication

Conversation

@darwin67

@darwin67 darwin67 commented Aug 19, 2026 •

Copy link
Copy Markdown
Member

Summary

  • allow authenticated users to open settings and update non-sensitive paste defaults without reauthenticating
  • require recent authentication only when changing email/password or managing API tokens, with safe redirects for stale sessions
  • serialize email confirmations, bind tokens to their user, and atomically consume them
  • handle invalid direct password updates without crashing and re-login using the server-returned user

Regression coverage

  • stale settings access and sensitive/non-sensitive mutation boundaries
  • cross-user and concurrent email-confirmation attempts
  • invalid and identity-field-free direct password submissions

Verification

  • nix develop -c mix precommit (454 tests passed)

@github-actions github-actions Bot added the fix label Aug 19, 2026
@darwin67
darwin67 merged commit df0c962 into main Aug 21, 2026
25 checks passed
@darwin67
darwin67 deleted the fix/settings-reauthentication branch August 21, 2026 05:42
@chaba2-bot chaba2-bot Bot mentioned this pull request Aug 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant