audit login flow end-to-end #228

Closed
opened 2026-04-08 02:35:57 +00:00 by barrettruth · 1 comment
barrettruth commented 2026-04-08 02:35:57 +00:00

Revisit the login flow after the current settings and reminders cleanup and do a full end-to-end UX pass.

Check the main path from login through post-auth redirect, plus OAuth provider errors, passkey/WebAuthn RP ID and origin handling, 2FA verification, recovery, logout/re-entry, and the onboarding handoff for a fresh session.

This should include the redirect-uri class of failures seen during the Forgejo/VPS migration.

Revisit the login flow after the current settings and reminders cleanup and do a full end-to-end UX pass. Check the main path from login through post-auth redirect, plus OAuth provider errors, passkey/WebAuthn RP ID and origin handling, 2FA verification, recovery, logout/re-entry, and the onboarding handoff for a fresh session. This should include the redirect-uri class of failures seen during the Forgejo/VPS migration.
barrettruth added this to the v0.1.0 milestone 2026-05-10 20:16:28 +00:00
Owner

Change of plan: the full login/auth flow is being retired for a simpler self-hosted mode. Tracker #287 owns the shutdown work, so this audit should close with that PR instead of continuing the OAuth/WebAuthn/TOTP flow.

Change of plan: the full login/auth flow is being retired for a simpler self-hosted mode. Tracker #287 owns the shutdown work, so this audit should close with that PR instead of continuing the OAuth/WebAuthn/TOTP flow.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
barrettruth/delta#228
No description provided.