From 7403bb1d933e83d3c3d2c795a3f2ee56bf2e13f0 Mon Sep 17 00:00:00 2001 From: Sterling Archer Date: Thu, 18 Jun 2026 19:09:20 -0700 Subject: [PATCH] Branded magic link email, rate limiting, security improvements --- config.js | 1 + index.html | 8 +++----- 2 files changed, 4 insertions(+), 5 deletions(-) diff --git a/config.js b/config.js index 411b9fc..90bd51f 100644 --- a/config.js +++ b/config.js @@ -9,5 +9,6 @@ window.STEPMATES_CONFIG = { }, webhookBase: "https://webhook-mgc3i5pbxq-uc.a.run.app", adminNotifyUrl: "https://adminnotify-mgc3i5pbxq-uc.a.run.app", + sendMagicLinkUrl: "https://sendmagiclink-mgc3i5pbxq-uc.a.run.app", appUrl: "https://justinoros.github.io/step-tracker" }; diff --git a/index.html b/index.html index 1b06bc8..68a7797 100644 --- a/index.html +++ b/index.html @@ -1555,11 +1555,9 @@ window.sendMagicLink = async function() { btn.disabled = true; btn.innerHTML = ' Sending…'; try { - const continueUrl = APP_URL + '?email=' + encodeURIComponent(email); - await sendSignInLinkToEmail(auth, email, { - url: continueUrl, - handleCodeInApp: true - }); + const res = await fetch(`${window.STEPMATES_CONFIG.sendMagicLinkUrl}?email=${encodeURIComponent(email)}`); + const data = await res.json(); + if (!res.ok) throw new Error(data.error || 'Failed to send'); localStorage.setItem('emailForSignIn', email); document.getElementById('auth-card').style.display = 'none'; document.getElementById('magic-sent-card').style.display = 'block';