Branded magic link email, rate limiting, security improvements
This commit is contained in:
1 parent
b3bb2f13b7
commit
7403bb1d93
2 files changed
+4
-5
No files matched your search
+3
-5
@@ -1555,11 +1555,9 @@ window.sendMagicLink = async function() {
|
||||
btn.disabled = true;
|
||||
btn.innerHTML = '<span class="spinner"></span> Sending…';
|
||||
try {
|
||||
const continueUrl = APP_URL + '?email=' + encodeURIComponent(email);
|
||||
await sendSignInLinkToEmail(auth, email, {
|
||||
url: continueUrl,
|
||||
handleCodeInApp: true
|
||||
});
|
||||
const res = await fetch(`${window.STEPMATES_CONFIG.sendMagicLinkUrl}?email=${encodeURIComponent(email)}`);
|
||||
const data = await res.json();
|
||||
if (!res.ok) throw new Error(data.error || 'Failed to send');
|
||||
localStorage.setItem('emailForSignIn', email);
|
||||
document.getElementById('auth-card').style.display = 'none';
|
||||
document.getElementById('magic-sent-card').style.display = 'block';
|
||||
|
||||
Reference in new issue
Block a user