backend integration started
This commit is contained in:
@@ -77,6 +77,35 @@ export async function login(email: string, password: string): Promise<SessionUse
|
||||
return session;
|
||||
}
|
||||
|
||||
/** The backend's floor, enforced here too so the refusal is instant. */
|
||||
export const MIN_PASSWORD_LENGTH = 6;
|
||||
|
||||
/**
|
||||
* Sets the password on an account that has never had one.
|
||||
*
|
||||
* `PUT /users/update` doubles as the password call. There is no dedicated
|
||||
* endpoint and no reset flow — the controller says so in as many words
|
||||
* (`userController.go:145`): "this endpoint also doubles as the
|
||||
* password-setup/reset call (userid + password only, everything else left zero
|
||||
* so GORM's `Updates` skips it)". Sending only those two fields is therefore
|
||||
* load-bearing: a struct with any other field populated would write it.
|
||||
*
|
||||
* This is reachable only with the `userid` that `applogin` just handed back for
|
||||
* an account it confirmed has an empty password. It is not a "change my
|
||||
* password" call and must not be wired up as one — nothing here verifies the
|
||||
* old password, because there is no old password.
|
||||
*
|
||||
* Passwords are stored in clear on this backend. That is not something the
|
||||
* console can fix, and it is the reason this flow exists at all rather than an
|
||||
* emailed setup link.
|
||||
*/
|
||||
export async function setInitialPassword(userid: number, password: string): Promise<void> {
|
||||
if (password.length < MIN_PASSWORD_LENGTH) {
|
||||
throw new Error(`Use at least ${MIN_PASSWORD_LENGTH} characters.`);
|
||||
}
|
||||
await api.put<unknown>(`${WEB}/users/update`, { userid, password });
|
||||
}
|
||||
|
||||
/**
|
||||
* The backend's own words, where they are usable, and ours where they are not.
|
||||
*
|
||||
|
||||
Reference in New Issue
Block a user