Skip to content

feat(api): forgot-password, email change, gas-tank status, payment-links authz matrix - #387

Merged
Emmyt24 merged 7 commits into
Octo-Protocol-org:dev-branchfrom
aishatumba5-svg:feat/api/auth-recovery-gas-tank-authz-matrix
Sep 28, 2026
Merged

Emmyt24 merged 7 commits into
Octo-Protocol-org:dev-branchfrom
aishatumba5-svg:feat/api/auth-recovery-gas-tank-authz-matrix

Conversation

@aishatumba5-svg

@aishatumba5-svg aishatumba5-svg commented Sep 26, 2026 •

Copy link
Copy Markdown

Summary

Security hardening found along the way

  • OTP consumption is now an atomic claim, so concurrent submissions can't both redeem one code.
  • Email templates HTML-escape interpolated addresses (the new old-address notice would otherwise let an attacker inject content into a victim's inbox).

Notes

  • Adds migrations 0021 (session epoch, password_reset OTP purpose) and 0022 (email_change purpose).
  • Known, not fixed here: the 5-attempt OTP limit can be raced with parallel guesses (bounded by the per-IP limit); Store::revoke_token/is_token_revoked reference a non-existent column and look like dead code.

Test plan

  • cargo test -p octo-api new suites: password_reset_tests, email_change_tests, authz_matrix_tests, gas-tank tests in api_tests
  • auth_tests, session_revocation_tests, store_tests (regression)
  • cargo fmt --check, cargo clippy -D warnings

Closes #323
Closes #324
Closes #325
Closes #326

There was no dedicated read endpoint for a wallet's gas-tank status, forcing a dashboard
to either lack this data or infer it awkwardly from other responses. Adds a focused
GET route returning the tank's account, provisioning state, and today's budget spend.
payment_links.rs mixes owner-authenticated and fully-public routes with no consolidated
authorization regression test, unlike other route groups already covered by
authz_matrix_tests.rs. Extends the same matrix pattern to this file.
There was no recovery path for a user locked out of their account. Adds a request/confirm
password-reset pair reusing the existing OTP infrastructure, with the same
account-enumeration protection already established for login/signup.
There was no way to change a user's login email. Adds a two-step request/confirm flow
that verifies control of the new address via OTP before applying the change, so a typo
or attacker-supplied address can't silently take over the account's login identity.
@drips-wave

drips-wave Bot commented Sep 26, 2026

Copy link
Copy Markdown

@aishatumba5-svg Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

…-recovery-gas-tank-authz-matrix

# Conflicts:
#	crates/api/src/auth.rs
#	crates/api/tests/api_tests.rs
#	crates/email/src/templates.rs
#	crates/store/src/lib.rs
#	crates/store/tests/store_tests.rs
#	docs/openapi.yaml
@Emmyt24
Emmyt24 merged commit 2e0a47b into Octo-Protocol-org:dev-branch Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants