fix(api): require reauthentication for changes to own email and passkeys; update OpenAPI descriptions

This commit is contained in:
flyemoji committed 2026-09-29 13:39:35 +09:00
1 parent f7a826d635
commit 3922aae9a7
6 files changed
+149 -15

No files matched your search

+6 -2
View File
@@ -5864,7 +5864,7 @@ paths:
$ref: '#/components/responses/Unauthorized'
'403':
description: >-
Not an owner (forbidden); a change to the caller's own role (self_protected); or a role change on the owner account (owner_protected), which only the host's break-glass console (sudo felis breakGlass) may make.
Not an owner (forbidden); a change to the caller's own role (self_protected); a role change on the owner account (owner_protected), which only the host's break-glass console (sudo felis breakGlass) may make; or a change to the caller's own email without a reauth in the last 5 minutes (reauth_required).
content:
application/json:
schema: { $ref: '#/components/schemas/Error' }
@@ -6136,7 +6136,11 @@ paths:
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
description: >-
Not an owner (forbidden); or unbinding the caller's own passkeys without a reauth in the last 5 minutes (reauth_required).
content:
application/json:
schema: { $ref: '#/components/schemas/Error' }
/api/v1/users/{id}/links:
post: