feat(auth): GitHub OAuth login + SMS one-time-code login
Some checks failed
Deploy to Production / deploy (push) Failing after 1m8s
Some checks failed
Deploy to Production / deploy (push) Failing after 1m8s
GitHub: /v1/auth/github + /callback — authorization-code flow, fetches the verified primary email via /user/emails, reuses upsertOAuthLogin. SMS: phone is now a first-class login identity. - schema: users.email nullable, users.phone added, new sms_codes table. - @bmm/auth: issueSmsCode / consumeSmsCode — 6-digit code, hashed at rest, 10-min TTL, per-phone rate limit, 5-attempt cap, get-or-create user by phone. - apps/api: /v1/auth/sms/request + /verify, Twilio REST send (no SDK), per-IP throttle. /v1/auth/providers now reports google/github/sms. - login UI: Google + GitHub buttons, Email|Phone toggle, two-step SMS (number -> 6-digit code with one-time-code autofill). SMS link was rejected in favour of an OTP code — carrier link-scanners consume magic-link tokens before the user taps them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
10
.env.example
10
.env.example
@@ -11,10 +11,18 @@ BETTER_AUTH_URL=http://localhost:3001
|
||||
NEXT_PUBLIC_APP_URL=http://localhost:3001
|
||||
NEXT_PUBLIC_API_URL=http://localhost:4000
|
||||
|
||||
# ---- GitHub OAuth (optional in dev) ----
|
||||
# ---- GitHub OAuth ("Continue with GitHub") ----
|
||||
# Create at https://github.com/settings/applications/new
|
||||
# Authorized callback URL: <CONTROL_PLANE_PUBLIC_URL>/v1/auth/github/callback
|
||||
GITHUB_OAUTH_ID=
|
||||
GITHUB_OAUTH_SECRET=
|
||||
|
||||
# ---- Twilio SMS (phone one-time-code login) ----
|
||||
# Credentials + a verified sender number from the Twilio console.
|
||||
TWILIO_ACCOUNT_SID=
|
||||
TWILIO_AUTH_TOKEN=
|
||||
TWILIO_SMS_FROM=
|
||||
|
||||
# ---- Google OAuth (optional — "Continue with Google") ----
|
||||
# Create at https://console.cloud.google.com/apis/credentials
|
||||
# Authorized redirect URI must be: <CONTROL_PLANE_PUBLIC_URL>/v1/auth/google/callback
|
||||
|
||||
Reference in New Issue
Block a user