Skip to content

[PB-6913]: feat/add the account setup service - #2190

Merged
xabg2 merged 5 commits into
featurew/sign-up-passwordless-for-checkoutfrom
feat/PB-6913-account-setup-service
Oct 6, 2026
Merged

xabg2 merged 5 commits into
featurew/sign-up-passwordless-for-checkoutfrom
feat/PB-6913-account-setup-service

Conversation

@xabg2

@xabg2 xabg2 commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Description

First part of the account setup screen for customers who paid before creating their account (PB-6873). No visible change:

  • The sign-up crypto (password hash, mnemonic and keys) and the steps after registering (store the session, load the user and plan) are extracted from the sign-up so the account setup can reuse them. The sign-up keeps sending exactly the same data.
  • Adds the service and hooks that complete the account setup from the email link and resend that email.

Related Issues

  • PB-6913 (subtask of PB-6873)

Related Pull Requests

Checklist

  • Changes have been tested locally.
  • Unit tests have been written or updated as necessary.
  • The code adheres to the repository's coding standards.
  • Relevant documentation has been added or updated.
  • No new warnings or errors have been introduced.
  • SonarCloud issues have been reviewed and addressed.
  • QA Passed

Testing Process

Unit tests with the real crypto: the plain password never leaves the browser, the mnemonic decrypts with the password, the setup token and captcha are sent, the user is logged in with decrypted keys, and a rejected link leaves nobody logged in. The existing sign-up tests keep passing unchanged. tsc, lint and the sign-up, services and core test suites pass.

Additional Notes

Nothing calls the new service until the next PR adds the screen.

Add the services and hooks to complete the setup of an account paid
from checkout using the token from the account setup email, and
extract new-account credential generation out of the sign-up flow so
it can be reused.
@xabg2 xabg2 added the enhancement New feature or request label Sep 29, 2026
@xabg2 xabg2 self-assigned this Sep 29, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying drive-web with  Cloudflare Pages  Cloudflare Pages

Latest commit: 697dd7a
Status: ✅  Deploy successful!
Preview URL: https://8cc8484b.drive-web.pages.dev
Branch Preview URL: https://feat-pb-6913-account-setup-s.drive-web.pages.dev

View logs

@xabg2
xabg2 marked this pull request as ready for review September 30, 2026 09:45
* Messages the backend sends when the link can no longer be used. Other 403s (e.g. a failed
* captcha) must not be shown as an invalid link.
*/
const INVALID_LINK_MESSAGES = new Set(['Invalid token', 'Token expired']);

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is quite likely to stop working if there is even the slightest change to the message. Perhaps the status code alone should be enough, with the message included as an extra in the check

}

export const completeAccountSetup = async ({ setupToken, password, dispatch }: CompleteAccountSetupParams) => {
const captchaToken = await generateCaptchaToken();

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cloudflare’s Turnstile was recently added to the login process. I’m just mentioning this so we bear it in mind in case, in future, we prefer to use a single type of captcha for everything

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep, I know, but payments still works with captcha token... I have in mind to migrate it to Turnstile

@xabg2
xabg2 changed the base branch from master to featurew/sign-up-passwordless-for-checkout October 6, 2026 13:41
@xabg2
xabg2 merged commit 2eb6fc6 into featurew/sign-up-passwordless-for-checkout Oct 6, 2026
2 checks passed
@xabg2
xabg2 deleted the feat/PB-6913-account-setup-service branch October 6, 2026 14:04
@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
34.8% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants