One way in: email sign-in only; wallet-only sessions finish setup by email
- Remove the "sign in with just your wallet" door from the sign-in card. - A wallet-only session (no account) is walked to the email card with a finish-setup note; verifying the code links that wallet to the account and retires the wallet-only session, so member #, purchases and payouts stay attached and username/profile work. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
@@ -568,6 +568,16 @@ const server = http.createServer(async (req, res) => {
|
||||
const ref = parseCookies(req)['iap.sponsor'] || '';
|
||||
const r = await accounts.ensure(e, ref); // first touch wins; existing accounts unchanged
|
||||
if (r.error) return json(res, 400, r);
|
||||
// a wallet-only session (signed with a wallet, no account) finishing setup:
|
||||
// adopt that wallet into the email account so member #, purchases and
|
||||
// payouts stay attached, then retire the wallet-only session
|
||||
const prior = await auth.fromRequest(req);
|
||||
if (prior && prior.address && !prior.email) {
|
||||
const lr = await accounts.linkWallet(e, prior.address);
|
||||
if (lr.error) return json(res, 400, lr);
|
||||
r.account = lr.account || await accounts.byEmail(e);
|
||||
await auth.logout(req);
|
||||
}
|
||||
if (r.created) { sendWelcome(e, ref).catch(() => {}); } // sponsor notified at username set (/api/my/profile)
|
||||
if (r.created && b.newsletter) sendy.subscribe(r.account.email, r.account.username || '').catch(() => {}); // pre-checked opt-in, silent, new joins only
|
||||
let memberId = 0;
|
||||
@@ -577,7 +587,8 @@ const server = http.createServer(async (req, res) => {
|
||||
}
|
||||
|
||||
// -- wallet auth: link-to-account when an email session exists, or
|
||||
// wallet-first sign-in for crypto-native users
|
||||
// wallet-first sign-in (no UI door since 2026-09-09; a wallet-only session
|
||||
// is walked to the email card, which adopts the wallet on verify)
|
||||
if (p === '/api/auth/challenge' && req.method === 'POST') {
|
||||
const b = await readBody(req);
|
||||
const r = auth.makeChallenge(b.address);
|
||||
|
||||
Reference in New Issue
Block a user