refactor(api): drop dead password-era ResetMailer, reconcile passkey-unbind docs
The passwordless migration left ResetMailer (SendPasswordReset) and its API field with zero callers and no wiring; the web console authenticates via email-OTP and passkey only. Remove both, plus the now-orphaned context import that the interface was the last user of in handlers_users.go.
Reconcile the DeleteAllPasskeyCredentialsForUser docs in repo.go and pgrepo.go: they claimed there was no production caller, but 2f22027 wired the owner-tier DELETE /users/{id}/passkeys. Both now note that a complete authenticator remediation pairs the unbind with a session revoke (unbinding alone leaves the live hijacked session; revoking alone leaves a re-enrollable credential), and the OpenAPI operation carries the same guidance in a new description. Reword the stale local-password test-fake header, since the passwordless fakes carry no must_change_password field.
No behavior change. gofmt, build, and the full test tree are green; OpenAPI parity and passkey-unbind tests pass; a grep confirms ResetMailer/SendPasswordReset are gone from the Go tree.
This commit is contained in:
6 files changed
+19
-24
No files matched your search
@@ -605,10 +605,10 @@ func (f *fakeRepo) BackupByID(_ context.Context, id string) (*BackupRecord, erro
|
||||
return nil, ErrNotFound
|
||||
}
|
||||
|
||||
// ---- local-password auth fakes (spec §B) ----
|
||||
// ---- staff / session auth fakes (spec §B, passwordless) ----
|
||||
// Each method mirrors the PGRepo contract: a returned StaffUser is copied so a
|
||||
// test cannot mutate the stored row by reference, SessionUser re-reads the
|
||||
// CURRENT staff flags (so a password change clears must_change_password for live
|
||||
// CURRENT staff row (so a role change or a deleted account takes effect on live
|
||||
// sessions just as the PG JOIN does), and the settings/sessions semantics match.
|
||||
|
||||
func (f *fakeRepo) UserByUsername(_ context.Context, username string) (*StaffUser, error) {
|
||||
|
||||
Reference in new issue
Block a user