audit login flow end-to-end #228
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
status:blocked
track:api
track:auto
track:core
track:deploy
track:infra
track:ui
type:cleanup
type:docs
type:epic
type:release
type:research
wontfix
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
barrettruth/delta#228
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Revisit the login flow after the current settings and reminders cleanup and do a full end-to-end UX pass.
Check the main path from login through post-auth redirect, plus OAuth provider errors, passkey/WebAuthn RP ID and origin handling, 2FA verification, recovery, logout/re-entry, and the onboarding handoff for a fresh session.
This should include the redirect-uri class of failures seen during the Forgejo/VPS migration.
Change of plan: the full login/auth flow is being retired for a simpler self-hosted mode. Tracker #287 owns the shutdown work, so this audit should close with that PR instead of continuing the OAuth/WebAuthn/TOTP flow.