Handlingar
Features #38
öppen
CA
Features #19: P0 — Core stability and finish current features
[P0] Refine Login/Register authentication ordering and verification
Features #38:
[P0] Refine Login/Register authentication ordering and verification
Status:
Planned
Prioritet:
High
Tilldelad:
-
Startdatum:
2026-08-29
Deadline:
% Klart:
10%
Beräknad tid:
Reported by:
Beskrivning
Imported from the pre-Redmine CookieMonsters TODO during the 2026-08-29 migration.
Original priority: P0 — Core stability and finish current features
- Refine Login/Register authentication ordering and verification:
- recommended sign-in providers/actions are at the top of the login/register panel;
- Email login is presented as the classic fallback rather than the primary route;
- Create account keeps classic email signup collapsed until selected; the obsolete “Back to sign-up methods” control is removed;
- Code of Conduct acceptance is mandatory for every account-creation method, not only classic email signup;
- require a clear explicit, initially unchecked I agree to the Code of Conduct acknowledgement for new-account creation through Discord, Windows Hello / YubiKey, classic email signup and any future registration provider;
- the acknowledgement must link to the same canonical
/code-of-conduct/page used elsewhere on CookieMonsters; - for providers that combine sign-in and registration (such as Discord), do not accidentally require existing members to accept the CoC every time they log in: enforce acceptance when the provider is being used to create a new CookieMonsters account, either before launching the provider flow from Create account or as a mandatory post-provider onboarding gate before the account becomes active;
- a direct OAuth callback, crafted frontend request or alternate API path must not be able to create/activate an account without valid CoC acceptance; enforce the requirement server-side as well as in the UI;
- store an acceptance timestamp and the accepted Code of Conduct version/revision with the account so consent can be audited and future material CoC changes can request explicit re-consent deliberately instead of silently assuming it;
- keep login for already-created accounts separate from registration consent unless a future CoC revision explicitly requires re-consent;
- Discord login and the revised Create account UI were live-verified on 2026-08-19;
- MFA login challenge, TOTP verification, backup-code recovery and trust-device UI are implemented in source;
- MFA live end-to-end verification is deliberately deferred and must remain on TODO, but it does not block continuing normal CookieMonsters work because Discord is the primary login method for most members;
- later verify MFA enrolment/setup, successful challenge during login, invalid-code handling, backup-code recovery, disable flow and server-side enforcement.
CM-TODO-ID:9c583addcb6fcc40c6e3
Future notes, acceptance criteria and status changes belong in this Redmine issue.
Handlingar