refactor: update Dockerfile and authentication flow for improved user experience
All checks were successful
Deploy / deploy (push) Successful in 15m6s

- Updated Dockerfile to create a cache directory for Next.js runtime, ensuring proper permissions and ownership.
- Enhanced the authentication flow by updating the magic link expiration time from 5 to 15 minutes, improving user experience and reducing login issues.
- Added user-friendly error handling for invalid or expired magic links, providing clear feedback on the login page.
- Adjusted email templates to reflect the new 15-minute validity period for magic links.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
bilalgursen
2026-08-07 02:05:14 +03:00
parent 37baeb9172
commit be4b2c6000
19 changed files with 444 additions and 134 deletions

View File

@@ -6,20 +6,37 @@ import { grantCredits, DENEME_KREDISI } from "./credits";
import { magicLinkEpostasi } from "./eposta";
import { epostaGonder } from "./eposta-gonder";
/**
* Verify URL'ini maile konacak onay sayfası URL'ine çevirir. Doğrulama linki
* GET'lendiği anda token'ı tüketen tek kullanımlık bir uçtur; mail güvenlik
* tarayıcıları (SafeLinks vb.) ve tarayıcı ön-yüklemeleri linki kullanıcıdan
* önce "ziyaret edip" token'ı yakıyordu. Maildeki link bu yüzden token'ı
* tüketmeyen /giris/dogrula sayfasına gider; verify ancak oradaki butonla
* tetiklenir.
*/
function onaySayfasiUrl(verifyUrl: string): string {
const kaynak = new URL(verifyUrl);
const hedef = new URL("/giris/dogrula", kaynak.origin);
hedef.search = kaynak.search;
return hedef.toString();
}
async function sendMagicLinkEmail(email: string, url: string) {
if (process.env.NODE_ENV !== "production") {
// Dev paneli "anında giriş" için son üretilen linki yakalar (bkz.
// src/lib/dev/actions.ts) — prod'da asla çalışmaz.
// src/lib/dev/actions.ts) — panel onay adımını atlayıp doğrudan verify
// URL'ine gittiği için ham link saklanır. Prod'da asla çalışmaz.
(globalThis as { __sonMagicLink?: string }).__sonMagicLink = url;
}
const mailLinki = onaySayfasiUrl(url);
if (!process.env.RESEND_API_KEY) {
// Dev fallback: Resend anahtarı yoksa linki terminale yaz
console.log(`\n[giris] Magic link for ${email}:\n${url}\n`);
console.log(`\n[giris] Magic link for ${email}:\n${mailLinki}\n`);
return;
}
// Gönderim hatası better-auth'a fırlatılır — aksi halde kullanıcı
// "gönderildi" ekranını görür ama mail hiç çıkmaz.
await epostaGonder(email, magicLinkEpostasi(url));
await epostaGonder(email, magicLinkEpostasi(mailLinki));
}
export const auth = betterAuth({
@@ -54,6 +71,10 @@ export const auth = betterAuth({
},
plugins: [
magicLink({
// Varsayılan 5 dk, mail gecikmesi + onay adımı için 15 dk'ya çıkarıldı.
// Süreyi değiştirirken e-posta metnini (src/lib/eposta.ts) ve giriş
// ekranındaki "gönderildi" mesajını (giris-form.tsx) da güncelle.
expiresIn: 900,
sendMagicLink: async ({ email, url }) => {
await sendMagicLinkEmail(email, url);
},