Skip to content

bug(gotrue): password sign-in can't send a captcha token #452

Description

@fresh55

Api.SignInWithEmail and Api.SignInWithPhone only take the identifier and the password, and every password SignIn in Client and StatelessClient goes through them, so there is no way to send a captcha token.

await client.SignIn(email, password);
// POST /token?grant_type=password with only email and password in the body

With CAPTCHA protection on, the server checks this grant too (isIgnoreCaptchaRoute), so password sign-in is rejected. Sign-up has the same gap in #213.

auth-js takes a captcha token on password sign-in, and so do the other SDKs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions