Skip to content

Make dashboard sign-up and password reset work with email confirmation; release 0.13.5 - #88

Merged
nielsrolf merged 1 commit into
mainfrom
fix/auth-email-flows
Sep 29, 2026
Merged

nielsrolf merged 1 commit into
mainfrom
fix/auth-email-flows

Conversation

@nielsrolf

Copy link
Copy Markdown
Collaborator

What changes

  • Sign-up: AuthContext.signUp now returns needsConfirmation when Supabase doesn't return a session. The signup form then says "we sent a confirmation link" instead of trying to sign in immediately. The confirmation link now leads to /organizations.
  • Password reset: the global onAuthStateChange handler sends PASSWORD_RECOVERY to /reset-password. Previously, a recovery link that Supabase redirected to the Site URL simply logged the user in, so the reset email behaved like a login link.
  • Release: version bumped to 0.13.5, docs/release-0.13.5.md added, and the dashboard rebuilt into backend/static. IMAGE_VERSION is unchanged (v0.13.4), since this is a frontend-only change.

Hosted project settings (already applied to prod-ow, not in the repo)

The root cause of the broken reset was that the Site URL was http://localhost:3000 and the redirect allowlist was empty. Now set:

  • Site URL: https://openweights.nielsrolf.com
  • Redirect allowlist: https://openweights.nielsrolf.com/**
  • Custom SMTP: Resend, from noreply@mail.nielsrolf.com, rate limit 30/h
  • "Confirm email": on

The CLI ow signup already handles confirmation-required, since it stops and asks the user to confirm.

Testing

  • tsc --noEmit -p tsconfig.app.json is clean.
  • npm run build succeeds, and the bundle contains the recovery redirect.
  • A real recovery email was sent through prod with Resend SMTP, redirecting to /reset-password.

🤖 Generated with Claude Code

…n; release 0.13.5

- Sign-up only signs in when Supabase returns a session; with "Confirm email"
  on it shows a check-your-inbox message instead of attempting a sign-in.
  The confirmation link returns to /organizations.
- A PASSWORD_RECOVERY auth event anywhere routes to /reset-password, so a
  recovery link that Supabase redirected to the Site URL no longer just logs
  the user in.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@nielsrolf
nielsrolf merged commit 2e70b82 into main Sep 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant