Skip to main content

Module magic

Module magic 

Source
Expand description

Magic links: a 32-byte random token, stored hashed, valid for 15 minutes, usable once.

The emailed link opens a small confirm page that POSTs the token back. Mail scanners that prefetch every link in an email only issue a GET, so they can’t burn the single-use token before the person clicks it.

Structs§

AuditLink
A no-signup audit a sign-in link should attach to the new account when it is used.
Card
What the login card shows.
CardPartial
ConfirmPage
LoginForm
LoginPage
LoginQuery

Enums§

LinkOutcome
What issue_link did.

Constants§

MAGIC_TTL

Functions§

asset
Template helper so auth pages can reference assets without the app shell.
confirm_page
consume
issue_link
Stores a magic-link token for address and emails the link. With an audit, the link also carries the audit’s crawl id, and using it attaches the audited site to the account. Those links are capped per audit and per recipient (see quick::create_unlock_token).
login_page
request_link
signups_closed