From c6fd7ea89b6e0a96eb1d81989de891b4768b1044 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Mon, 31 Aug 2026 17:19:17 +0200 Subject: feat: email verification for registration, email change, and invitations Registration now creates a pending account and sends a 6-digit code via email; the account activates only after verification. Email changes on the profile page follow the same flow. Group invitations send a notification email to the invitee (without revealing their address to the inviter) containing the invite code and hub link. Backend: blind HMAC-SHA256 email index for uniqueness without decryption, mail.py for localhost Postfix delivery, verification endpoints, cleanup of expired codes and stale pending accounts, startup backfill of email_hash for existing users. Frontend: 3-phase register page, inline email change verification on profile, invite-notify call with status display. All 10 locales updated. Co-Authored-By: Claude Opus 4.6 --- .../meshbay-hub/src/meshbay_hub/tasks/cleanup.py | 28 +++++++++++++++++++++- 1 file changed, 27 insertions(+), 1 deletion(-) (limited to 'packages/meshbay-hub/src/meshbay_hub/tasks') diff --git a/packages/meshbay-hub/src/meshbay_hub/tasks/cleanup.py b/packages/meshbay-hub/src/meshbay_hub/tasks/cleanup.py index c387100..6fa62a4 100644 --- a/packages/meshbay-hub/src/meshbay_hub/tasks/cleanup.py +++ b/packages/meshbay-hub/src/meshbay_hub/tasks/cleanup.py @@ -7,7 +7,7 @@ from datetime import datetime, timedelta, timezone from sqlalchemy import delete, select from sqlalchemy.ext.asyncio import AsyncSession -from meshbay_hub.db.models import Group, GroupMember, IPLog +from meshbay_hub.db.models import EmailVerification, Group, GroupMember, IPLog, User log = logging.getLogger(__name__) @@ -22,6 +22,26 @@ async def purge_old_ip_logs(db: AsyncSession, retention_days: int = RETENTION_DA return result.rowcount +PENDING_USER_EXPIRY_DAYS = 7 + + +async def purge_expired_verifications(db: AsyncSession) -> int: + now = datetime.now(timezone.utc) + result = await db.execute( + delete(EmailVerification).where(EmailVerification.expires_at < now)) + await db.commit() + return result.rowcount + + +async def purge_stale_pending_users(db: AsyncSession, + expiry_days: int = PENDING_USER_EXPIRY_DAYS) -> int: + cutoff = datetime.now(timezone.utc) - timedelta(days=expiry_days) + result = await db.execute( + delete(User).where(User.status == "pending", User.created_at < cutoff)) + await db.commit() + return result.rowcount + + async def cleanup_loop(get_session): """Run cleanup once at startup, then every 24 hours.""" try: @@ -31,6 +51,12 @@ async def cleanup_loop(get_session): deleted = await purge_old_ip_logs(db) if deleted: log.info("Purged %d IP log entries older than %d days", deleted, RETENTION_DAYS) + expired = await purge_expired_verifications(db) + if expired: + log.info("Purged %d expired email verifications", expired) + stale = await purge_stale_pending_users(db) + if stale: + log.info("Purged %d stale pending users", stale) except asyncio.CancelledError: raise except Exception as e: -- cgit v1.2.3