refactor(api): drop dead password-era ResetMailer, reconcile passkey-unbind docs
The passwordless migration left ResetMailer (SendPasswordReset) and its API field with zero callers and no wiring; the web console authenticates via email-OTP and passkey only. Remove both, plus the now-orphaned context import that the interface was the last user of in handlers_users.go.
Reconcile the DeleteAllPasskeyCredentialsForUser docs in repo.go and pgrepo.go: they claimed there was no production caller, but 2f22027 wired the owner-tier DELETE /users/{id}/passkeys. Both now note that a complete authenticator remediation pairs the unbind with a session revoke (unbinding alone leaves the live hijacked session; revoking alone leaves a re-enrollable credential), and the OpenAPI operation carries the same guidance in a new description. Reword the stale local-password test-fake header, since the passwordless fakes carry no must_change_password field.
No behavior change. gofmt, build, and the full test tree are green; OpenAPI parity and passkey-unbind tests pass; a grep confirms ResetMailer/SendPasswordReset are gone from the Go tree.
This commit is contained in:
6 files changed
+19
-24
No files matched your search
@@ -1020,9 +1020,9 @@ func (p *PGRepo) DeletePasskeyCredential(ctx context.Context, userID, id string)
|
||||
// single-credential delete this does NOT report ErrNotFound on zero rows: removing all of
|
||||
// a user's passkeys when they have none is a successful no-op, since "the user holds no
|
||||
// passkeys" is exactly the intended post-condition. It is the remediation that stops a
|
||||
// passkey planted through a transiently-hijacked session from surviving; its original
|
||||
// caller (the change-password flow) was removed in the passwordless migration, so it is
|
||||
// currently uncalled, retained for the account-remediation/reset path (P5, #78).
|
||||
// passkey planted through a transiently-hijacked session from surviving; its production
|
||||
// caller is the owner-tier DELETE /users/{id}/passkeys, which a complete remediation
|
||||
// pairs with a session revoke (unbinding alone leaves the live hijacked session).
|
||||
func (p *PGRepo) DeleteAllPasskeyCredentialsForUser(ctx context.Context, userID string) error {
|
||||
_, err := p.db.ExecContext(ctx,
|
||||
`DELETE FROM webauthn_credentials WHERE user_id = $1`, userID)
|
||||
|
||||
Reference in new issue
Block a user