refactor: update Dockerfile and authentication flow for improved user experience
All checks were successful
Deploy / deploy (push) Successful in 15m6s
All checks were successful
Deploy / deploy (push) Successful in 15m6s
- Updated Dockerfile to create a cache directory for Next.js runtime, ensuring proper permissions and ownership. - Enhanced the authentication flow by updating the magic link expiration time from 5 to 15 minutes, improving user experience and reducing login issues. - Added user-friendly error handling for invalid or expired magic links, providing clear feedback on the login page. - Adjusted email templates to reflect the new 15-minute validity period for magic links. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -6,20 +6,37 @@ import { grantCredits, DENEME_KREDISI } from "./credits";
|
||||
import { magicLinkEpostasi } from "./eposta";
|
||||
import { epostaGonder } from "./eposta-gonder";
|
||||
|
||||
/**
|
||||
* Verify URL'ini maile konacak onay sayfası URL'ine çevirir. Doğrulama linki
|
||||
* GET'lendiği anda token'ı tüketen tek kullanımlık bir uçtur; mail güvenlik
|
||||
* tarayıcıları (SafeLinks vb.) ve tarayıcı ön-yüklemeleri linki kullanıcıdan
|
||||
* önce "ziyaret edip" token'ı yakıyordu. Maildeki link bu yüzden token'ı
|
||||
* tüketmeyen /giris/dogrula sayfasına gider; verify ancak oradaki butonla
|
||||
* tetiklenir.
|
||||
*/
|
||||
function onaySayfasiUrl(verifyUrl: string): string {
|
||||
const kaynak = new URL(verifyUrl);
|
||||
const hedef = new URL("/giris/dogrula", kaynak.origin);
|
||||
hedef.search = kaynak.search;
|
||||
return hedef.toString();
|
||||
}
|
||||
|
||||
async function sendMagicLinkEmail(email: string, url: string) {
|
||||
if (process.env.NODE_ENV !== "production") {
|
||||
// Dev paneli "anında giriş" için son üretilen linki yakalar (bkz.
|
||||
// src/lib/dev/actions.ts) — prod'da asla çalışmaz.
|
||||
// src/lib/dev/actions.ts) — panel onay adımını atlayıp doğrudan verify
|
||||
// URL'ine gittiği için ham link saklanır. Prod'da asla çalışmaz.
|
||||
(globalThis as { __sonMagicLink?: string }).__sonMagicLink = url;
|
||||
}
|
||||
const mailLinki = onaySayfasiUrl(url);
|
||||
if (!process.env.RESEND_API_KEY) {
|
||||
// Dev fallback: Resend anahtarı yoksa linki terminale yaz
|
||||
console.log(`\n[giris] Magic link for ${email}:\n${url}\n`);
|
||||
console.log(`\n[giris] Magic link for ${email}:\n${mailLinki}\n`);
|
||||
return;
|
||||
}
|
||||
// Gönderim hatası better-auth'a fırlatılır — aksi halde kullanıcı
|
||||
// "gönderildi" ekranını görür ama mail hiç çıkmaz.
|
||||
await epostaGonder(email, magicLinkEpostasi(url));
|
||||
await epostaGonder(email, magicLinkEpostasi(mailLinki));
|
||||
}
|
||||
|
||||
export const auth = betterAuth({
|
||||
@@ -54,6 +71,10 @@ export const auth = betterAuth({
|
||||
},
|
||||
plugins: [
|
||||
magicLink({
|
||||
// Varsayılan 5 dk, mail gecikmesi + onay adımı için 15 dk'ya çıkarıldı.
|
||||
// Süreyi değiştirirken e-posta metnini (src/lib/eposta.ts) ve giriş
|
||||
// ekranındaki "gönderildi" mesajını (giris-form.tsx) da güncelle.
|
||||
expiresIn: 900,
|
||||
sendMagicLink: async ({ email, url }) => {
|
||||
await sendMagicLinkEmail(email, url);
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user