Branded magic link email, rate limiting, security improvements

This commit is contained in:
Sterling Archer committed 2026-06-18 19:09:20 -07:00
1 parent b3bb2f13b7
commit 7403bb1d93
2 files changed
+4 -5

No files matched your search

+3 -5
View File
@@ -1555,11 +1555,9 @@ window.sendMagicLink = async function() {
btn.disabled = true;
btn.innerHTML = '<span class="spinner"></span> Sending…';
try {
const continueUrl = APP_URL + '?email=' + encodeURIComponent(email);
await sendSignInLinkToEmail(auth, email, {
url: continueUrl,
handleCodeInApp: true
});
const res = await fetch(`${window.STEPMATES_CONFIG.sendMagicLinkUrl}?email=${encodeURIComponent(email)}`);
const data = await res.json();
if (!res.ok) throw new Error(data.error || 'Failed to send');
localStorage.setItem('emailForSignIn', email);
document.getElementById('auth-card').style.display = 'none';
document.getElementById('magic-sent-card').style.display = 'block';