Conversation
Add the services and hooks to complete the setup of an account paid from checkout using the token from the account setup email, and extract new-account credential generation out of the sign-up flow so it can be reused.
Deploying drive-web with
|
| Latest commit: |
697dd7a
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://8cc8484b.drive-web.pages.dev |
| Branch Preview URL: | https://feat-pb-6913-account-setup-s.drive-web.pages.dev |
xabg2
marked this pull request as ready for review
September 30, 2026 09:45
CandelR
approved these changes
Oct 6, 2026
| * Messages the backend sends when the link can no longer be used. Other 403s (e.g. a failed | ||
| * captcha) must not be shown as an invalid link. | ||
| */ | ||
| const INVALID_LINK_MESSAGES = new Set(['Invalid token', 'Token expired']); |
Collaborator
There was a problem hiding this comment.
This is quite likely to stop working if there is even the slightest change to the message. Perhaps the status code alone should be enough, with the message included as an extra in the check
| } | ||
|
|
||
| export const completeAccountSetup = async ({ setupToken, password, dispatch }: CompleteAccountSetupParams) => { | ||
| const captchaToken = await generateCaptchaToken(); |
Collaborator
There was a problem hiding this comment.
Cloudflare’s Turnstile was recently added to the login process. I’m just mentioning this so we bear it in mind in case, in future, we prefer to use a single type of captcha for everything
Contributor
Author
There was a problem hiding this comment.
Yep, I know, but payments still works with captcha token... I have in mind to migrate it to Turnstile
…913-account-setup-service
xabg2
changed the base branch from
master
to
featurew/sign-up-passwordless-for-checkout
October 6, 2026 13:41
…B-6913-account-setup-service
xabg2
merged commit Oct 6, 2026
2eb6fc6
into
featurew/sign-up-passwordless-for-checkout
2 checks passed
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Description
First part of the account setup screen for customers who paid before creating their account (PB-6873). No visible change:
Related Issues
Related Pull Requests
completeAccountSetup,resendAccountSetupEmail)Checklist
Testing Process
Unit tests with the real crypto: the plain password never leaves the browser, the mnemonic decrypts with the password, the setup token and captcha are sent, the user is logged in with decrypted keys, and a rejected link leaves nobody logged in. The existing sign-up tests keep passing unchanged.
tsc, lint and the sign-up, services and core test suites pass.Additional Notes
Nothing calls the new service until the next PR adds the screen.