fix(identity): staging fixed-code sign-in skips the first-password step (BUG-1152)
Independent Staging Quality Gate / validate (push) Successful in 12m25s
Independent Staging Quality Gate / publish (push) Successful in 3m56s

On the staging test-OTP channel, 验证码登录 with a fresh mailbox no longer
stops at 设置登录密码; it records consent and enters the app. 注册账号 still
sets a password, second factor still comes first, and production (no
IDENTITY_TEST_OTP) is unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N4f2nya58RoRu4yEmJgRGE
This commit is contained in:
Jesse_Chen
2026-10-01 22:43:34 +08:00
co-authored by Claude Opus 5.5
parent 279650a684
commit 2d620fb4ad
7 changed files with 98 additions and 3 deletions
+13 -2
View File
@@ -20,6 +20,15 @@ const AUTH_ERROR = "auth-error";
/** The staging fixed code stays up long enough to type it. */
const TEST_OTP_NOTICE_MS = 10_000;
/**
* Whether a code sign-in still asks for a first password. The staging fixed-code
* channel lets testers in with a fresh mailbox straight away (BUG-1152); choosing
* 注册账号 is asking for a password, so that path keeps the step.
*/
export function offersFirstPasswordStep(testMode: boolean, mode: AuthMode): boolean {
return !(testMode && mode === "otp");
}
function clearAuthNotices() {
dismissNotice(AUTH_NOTICE);
dismissNotice(AUTH_ERROR);
@@ -171,8 +180,10 @@ export function EmailOtpLogin({
notifyInfo("请输入验证器动态码,或使用一枚未使用的恢复码", { id: AUTH_NOTICE, duration: NOTICE_DURATION_MS.error });
return;
}
const hasPassword = await selfHostedAuthActions.hasPassword();
if (!hasPassword) {
if (
offersFirstPasswordStep(testMode, mode)
&& !(await selfHostedAuthActions.hasPassword())
) {
setStep("set-password");
notifySuccess("邮箱验证成功,请设置登录密码", { id: AUTH_NOTICE });
return;