One way in: email sign-in only; wallet-only sessions finish setup by email

- Remove the "sign in with just your wallet" door from the sign-in card.
- A wallet-only session (no account) is walked to the email card with a
  finish-setup note; verifying the code links that wallet to the account
  and retires the wallet-only session, so member #, purchases and payouts
  stay attached and username/profile work.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
martbost
2026-09-09 05:32:30 -05:00
parent c0bd4fcbdd
commit dd2ee4b77e
3 changed files with 20 additions and 15 deletions
+12 -1
View File
@@ -568,6 +568,16 @@ const server = http.createServer(async (req, res) => {
const ref = parseCookies(req)['iap.sponsor'] || '';
const r = await accounts.ensure(e, ref); // first touch wins; existing accounts unchanged
if (r.error) return json(res, 400, r);
// a wallet-only session (signed with a wallet, no account) finishing setup:
// adopt that wallet into the email account so member #, purchases and
// payouts stay attached, then retire the wallet-only session
const prior = await auth.fromRequest(req);
if (prior && prior.address && !prior.email) {
const lr = await accounts.linkWallet(e, prior.address);
if (lr.error) return json(res, 400, lr);
r.account = lr.account || await accounts.byEmail(e);
await auth.logout(req);
}
if (r.created) { sendWelcome(e, ref).catch(() => {}); } // sponsor notified at username set (/api/my/profile)
if (r.created && b.newsletter) sendy.subscribe(r.account.email, r.account.username || '').catch(() => {}); // pre-checked opt-in, silent, new joins only
let memberId = 0;
@@ -577,7 +587,8 @@ const server = http.createServer(async (req, res) => {
}
// -- wallet auth: link-to-account when an email session exists, or
// wallet-first sign-in for crypto-native users
// wallet-first sign-in (no UI door since 2026-09-09; a wallet-only session
// is walked to the email card, which adopts the wallet on verify)
if (p === '/api/auth/challenge' && req.method === 'POST') {
const b = await readBody(req);
const r = auth.makeChallenge(b.address);