feat(api): 添加或删除 passkey、修改邮箱前须 5 分钟内用已有因子重新验证,变更后邮件通知账户,面板加确认对话框与修改邮箱入口
This commit is contained in:
36 files changed
+2735
-288
No files matched your search
@@ -0,0 +1,7 @@
|
||||
-- When the holder of a session last proved a factor the account already had: a
|
||||
-- passkey assertion, a code mailed to the verified address, or a sign-in through
|
||||
-- one of those (op-login and the setup token count too). Adding or removing a
|
||||
-- passkey and changing the email need that proof within the last few minutes,
|
||||
-- so a stolen cookie alone cannot plant a lasting way in. NULL means the session
|
||||
-- never proved one (a bind-code sign-in), which is what every existing row gets.
|
||||
ALTER TABLE sessions ADD COLUMN reauth_at timestamptz;
|
||||
Reference in new issue
Block a user