feat(panel): expose owner passkey unbind in the user danger zone
DELETE /users/{id}/passkeys shipped as the owner-tier remediation for a
lost or compromised authenticator, but nothing in the panel reached it.
Add the danger-zone action with a confirm dialog; the account keeps its
other doors (email OTP, in-game op-login re-enrollment), so this severs
a credential without locking anyone out. Wire-shape test pins the call.
This commit is contained in:
5 files changed
+76
-4
No files matched your search
@@ -506,6 +506,13 @@ export const api = {
|
||||
revokeUserSession: (id: string, hash: string) =>
|
||||
request<{ ok: boolean }>("DELETE", `/users/${id}/sessions/${encodeURIComponent(hash)}`),
|
||||
|
||||
// unbindUserPasskeys severs EVERY passkey the user holds (owner-tier account
|
||||
// remediation for a lost or compromised authenticator). It is deliberately not
|
||||
// a lockout — the account keeps its other doors (email OTP, in-game op-login
|
||||
// re-enrollment). Unbinding an account that holds no passkeys is a 200 no-op.
|
||||
unbindUserPasskeys: (id: string) =>
|
||||
request<{ ok: boolean }>("DELETE", `/users/${id}/passkeys`),
|
||||
|
||||
linkAccount: (id: string, mcUuid: string, authSource?: string) =>
|
||||
request<{ ok: boolean; mc_uuid: string; auth_source: string }>(
|
||||
"POST",
|
||||
|
||||
Reference in new issue
Block a user