You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Product foundation: a supported-platform player can sign in, complete verification, manage working subscriptions and sign out without manual API calls. Confirm whether a separate frontend repository already exists before choosing an implementation home.
Existing capability
signIn.html is a sign-in reference, not a complete registration/preferences application. users/user.routes.js already provides session-based profile, CSRF, registration and JSON Patch endpoints. DIAGRAM.md documents the combined email+SMS confirmation flow. Reuse these contracts rather than redesigning identity.
First release scope
Bungie redirect/callback and credentialed session-cookie requests; no Bungie bearer token in frontend storage.
Registration form, email-link/SMS-code confirmation, expiry/retry handling, and privacy-preserving conflict responses.
CSRF token acquisition and required headers on mutations.
Only implemented subscription preferences; handle ETag/If-Match conflicts by refetching and asking the user to reconcile.
Reconnect/error states and sign-out.
Model API-facing session-cookie auth accurately in openapi.cjs, keeping Bungie OAuth documented as the upstream login flow; add the missing CSRF step to DIAGRAM.md. Related generated-client work: API Client #496.
Dependencies
Security: #713, #712, #711. Correctness: #718, #720, #722. Coordinate registration recovery with #571; do not require a speculative large state machine to ship basic UX.
Acceptance criteria
Existing frontend ownership/hosting and secure-cookie topology are confirmed before scaffolding a new app.
Playwright covers login, both verification proofs, expired attempt/retry, CSRF, preference update, stale ETag and sign-out across desktop/mobile.
Errors are actionable without leaking account-existence or internal details.
Only supported subscriptions are visible; disabled/unimplemented features are not presented as working.
No access/refresh tokens or verification secrets appear in analytics or browser persistence unnecessarily.
Documented OpenAPI/session/CSRF behavior matches actual HTTP tests.
Measure aggregate started/completed registration and preference activation with privacy-safe events.
Non-goals
Landing-page redesign, billing UI, full inventory manager, new auth provider, and independent scaling infrastructure without evidence. Rough estimate: 1-2 engineer-weeks after prerequisites, subject to existing frontend state.
Outcome and priority
Product foundation: a supported-platform player can sign in, complete verification, manage working subscriptions and sign out without manual API calls. Confirm whether a separate frontend repository already exists before choosing an implementation home.
Existing capability
signIn.htmlis a sign-in reference, not a complete registration/preferences application.users/user.routes.jsalready provides session-based profile, CSRF, registration and JSON Patch endpoints.DIAGRAM.mddocuments the combined email+SMS confirmation flow. Reuse these contracts rather than redesigning identity.First release scope
openapi.cjs, keeping Bungie OAuth documented as the upstream login flow; add the missing CSRF step toDIAGRAM.md. Related generated-client work: API Client #496.Dependencies
Security: #713, #712, #711. Correctness: #718, #720, #722. Coordinate registration recovery with #571; do not require a speculative large state machine to ship basic UX.
Acceptance criteria
Non-goals
Landing-page redesign, billing UI, full inventory manager, new auth provider, and independent scaling infrastructure without evidence. Rough estimate: 1-2 engineer-weeks after prerequisites, subject to existing frontend state.