Projekt

Allmänt

Profil

Handlingar

Features #38

öppen
CA

Features #19: P0 — Core stability and finish current features

[P0] Refine Login/Register authentication ordering and verification

Features #38: [P0] Refine Login/Register authentication ordering and verification

Tillagd av Codex API för ungefär en månad sedan. Uppdaterad för ungefär en månad sedan.

Status:
Planned
Prioritet:
High
Tilldelad:
-
Startdatum:
2026-08-29
Deadline:
% Klart:

10%

Beräknad tid:
Reported by:

Beskrivning

Imported from the pre-Redmine CookieMonsters TODO during the 2026-08-29 migration.

Original priority: P0 — Core stability and finish current features

  • Refine Login/Register authentication ordering and verification:
    • recommended sign-in providers/actions are at the top of the login/register panel;
    • Email login is presented as the classic fallback rather than the primary route;
    • Create account keeps classic email signup collapsed until selected; the obsolete “Back to sign-up methods” control is removed;
    • Code of Conduct acceptance is mandatory for every account-creation method, not only classic email signup;
    • require a clear explicit, initially unchecked I agree to the Code of Conduct acknowledgement for new-account creation through Discord, Windows Hello / YubiKey, classic email signup and any future registration provider;
    • the acknowledgement must link to the same canonical /code-of-conduct/ page used elsewhere on CookieMonsters;
    • for providers that combine sign-in and registration (such as Discord), do not accidentally require existing members to accept the CoC every time they log in: enforce acceptance when the provider is being used to create a new CookieMonsters account, either before launching the provider flow from Create account or as a mandatory post-provider onboarding gate before the account becomes active;
    • a direct OAuth callback, crafted frontend request or alternate API path must not be able to create/activate an account without valid CoC acceptance; enforce the requirement server-side as well as in the UI;
    • store an acceptance timestamp and the accepted Code of Conduct version/revision with the account so consent can be audited and future material CoC changes can request explicit re-consent deliberately instead of silently assuming it;
    • keep login for already-created accounts separate from registration consent unless a future CoC revision explicitly requires re-consent;
    • Discord login and the revised Create account UI were live-verified on 2026-08-19;
    • MFA login challenge, TOTP verification, backup-code recovery and trust-device UI are implemented in source;
    • MFA live end-to-end verification is deliberately deferred and must remain on TODO, but it does not block continuing normal CookieMonsters work because Discord is the primary login method for most members;
    • later verify MFA enrolment/setup, successful challenge during login, invalid-code handling, backup-code recovery, disable flow and server-side enforcement.

CM-TODO-ID:9c583addcb6fcc40c6e3

Future notes, acceptance criteria and status changes belong in this Redmine issue.

Handlingar

Finns även som: PDF Atom