refactor(api): drop dead password-era ResetMailer, reconcile passkey-unbind docs
The passwordless migration left ResetMailer (SendPasswordReset) and its API field with zero callers and no wiring; the web console authenticates via email-OTP and passkey only. Remove both, plus the now-orphaned context import that the interface was the last user of in handlers_users.go.
Reconcile the DeleteAllPasskeyCredentialsForUser docs in repo.go and pgrepo.go: they claimed there was no production caller, but 2f22027 wired the owner-tier DELETE /users/{id}/passkeys. Both now note that a complete authenticator remediation pairs the unbind with a session revoke (unbinding alone leaves the live hijacked session; revoking alone leaves a re-enrollable credential), and the OpenAPI operation carries the same guidance in a new description. Reword the stale local-password test-fake header, since the passwordless fakes carry no must_change_password field.
No behavior change. gofmt, build, and the full test tree are green; OpenAPI parity and passkey-unbind tests pass; a grep confirms ResetMailer/SendPasswordReset are gone from the Go tree.
This commit is contained in:
6 files changed
+19
-24
No files matched your search
@@ -2720,6 +2720,14 @@ paths:
|
||||
tags: [users]
|
||||
operationId: unbindUserPasskeys
|
||||
summary: Unbind every passkey of a user (owner only) — authenticator remediation.
|
||||
description: >-
|
||||
Severs a compromised or planted authenticator that would otherwise outlive a
|
||||
session revoke. A complete remediation pairs this with revoking the user's
|
||||
sessions (DELETE /users/{id}/sessions/{hash}): unbinding the credential alone
|
||||
leaves the live hijacked session, and revoking sessions alone leaves a
|
||||
re-enrollable credential. It is not a lockout — the account re-enters via the
|
||||
email-OTP door or op-login and re-enrolls. Removing zero passkeys is a 200
|
||||
no-op, not a 404.
|
||||
x-felis-face: [external]
|
||||
x-felis-tier: owner
|
||||
security: [{ accessJWT: [] }]
|
||||
|
||||
Reference in new issue
Block a user