Branded magic link email, rate limiting, security improvements
This commit is contained in:
@@ -9,5 +9,6 @@ window.STEPMATES_CONFIG = {
|
|||||||
},
|
},
|
||||||
webhookBase: "https://webhook-mgc3i5pbxq-uc.a.run.app",
|
webhookBase: "https://webhook-mgc3i5pbxq-uc.a.run.app",
|
||||||
adminNotifyUrl: "https://adminnotify-mgc3i5pbxq-uc.a.run.app",
|
adminNotifyUrl: "https://adminnotify-mgc3i5pbxq-uc.a.run.app",
|
||||||
|
sendMagicLinkUrl: "https://sendmagiclink-mgc3i5pbxq-uc.a.run.app",
|
||||||
appUrl: "https://justinoros.github.io/step-tracker"
|
appUrl: "https://justinoros.github.io/step-tracker"
|
||||||
};
|
};
|
||||||
|
|||||||
+3
-5
@@ -1555,11 +1555,9 @@ window.sendMagicLink = async function() {
|
|||||||
btn.disabled = true;
|
btn.disabled = true;
|
||||||
btn.innerHTML = '<span class="spinner"></span> Sending…';
|
btn.innerHTML = '<span class="spinner"></span> Sending…';
|
||||||
try {
|
try {
|
||||||
const continueUrl = APP_URL + '?email=' + encodeURIComponent(email);
|
const res = await fetch(`${window.STEPMATES_CONFIG.sendMagicLinkUrl}?email=${encodeURIComponent(email)}`);
|
||||||
await sendSignInLinkToEmail(auth, email, {
|
const data = await res.json();
|
||||||
url: continueUrl,
|
if (!res.ok) throw new Error(data.error || 'Failed to send');
|
||||||
handleCodeInApp: true
|
|
||||||
});
|
|
||||||
localStorage.setItem('emailForSignIn', email);
|
localStorage.setItem('emailForSignIn', email);
|
||||||
document.getElementById('auth-card').style.display = 'none';
|
document.getElementById('auth-card').style.display = 'none';
|
||||||
document.getElementById('magic-sent-card').style.display = 'block';
|
document.getElementById('magic-sent-card').style.display = 'block';
|
||||||
|
|||||||
Reference in New Issue
Block a user