Expand description
Magic links: a 32-byte random token, stored hashed, valid for 15 minutes, usable once.
The emailed link opens a small confirm page that POSTs the token back. Mail scanners that prefetch every link in an email only issue a GET, so they can’t burn the single-use token before the person clicks it.
Structs§
- Audit
Link - A no-signup audit a sign-in link should attach to the new account when it is used.
- Card
- What the login card shows.
- Card
Partial - Confirm
Page - Login
Form - Login
Page - Login
Query
Enums§
- Link
Outcome - What
issue_linkdid.
Constants§
Functions§
- asset
- Template helper so auth pages can reference assets without the app shell.
- confirm_
page - consume
- issue_
link - Stores a magic-link token for
addressand emails the link. With anaudit, the link also carries the audit’s crawl id, and using it attaches the audited site to the account. Those links are capped per audit and per recipient (seequick::create_unlock_token). - login_
page - request_
link - signups_
closed