Add email + OTP sign-in flow for cloud sync
Replace the "drop a session token in a file" workflow with a real Chrome-style email login. The Cloudflare worker already had Better Auth's `email-otp` plugin wired into `SEND_EMAIL`; this commit builds the renderer-side counterpart. Worker side: - Move the OTP sender from `auth@elydora.com` to `browser@elydora.com` (wrangler.toml `allowed_sender_addresses` + better_auth.ts `EMAIL_OTP_FROM_ADDRESS`). Worker must be redeployed to pick this up. Client side (`ely_sync_client::email_otp`): - `send_email_otp(config, email)` POSTs `/api/auth/email-otp/send-verification-otp` with `{ email, type: "sign-in" }`. - `verify_email_otp(config, email, otp)` POSTs `/api/auth/sign-in/email-otp`, reads the Better Auth session token from the JSON body's `token` field with the `Set-Cookie: better-auth.session_token=…` header as the documented fallback channel, and returns it as a `BearerToken`. Shell side (`shell/auth.rs` + `shell/internal_pages/sync.rs`): - New `AuthFlowPhase` (Idle / SendingCode / AwaitingOtp / Verifying / Error) tracks the in-flight form. Two off-thread workers run the HTTP exchanges so the GPUI render loop never blocks. - Successful verify saves the bearer via `SyncEngine::install_bearer` and triggers an immediate snapshot upload, so the user is signed in + initial-synced in one click. - Sync settings page replaces the bare "Sync now" button row with an account card: when SignedOut → email field + Send code → OTP field + Verify / Resend; when signed in → an account chip + Sign out. - `trigger_cloud_sync_upload` no longer takes a `Context` param so the post-auth path can fire it from the inbox-drain pass without needing a window context.
This commit is contained in:
@@ -7,7 +7,7 @@ import { jsonResponse } from "./responses.js";
|
||||
const APP_NAME = "ELY Browser";
|
||||
const AUTH_BASE_PATH = "/api/auth";
|
||||
const AUTH_CALLBACK_URL = "ely://auth/callback";
|
||||
const EMAIL_OTP_FROM_ADDRESS = "auth@elydora.com";
|
||||
const EMAIL_OTP_FROM_ADDRESS = "browser@elydora.com";
|
||||
const EMAIL_OTP_EXPIRES_IN_SECONDS = 300;
|
||||
|
||||
type BetterAuthDatabase = NonNullable<BetterAuthOptions["database"]>;
|
||||
|
||||
Reference in New Issue
Block a user