Skip to content

feat/332 finish auth - #333

Merged
krisarmstrong merged 1 commit into
mainfrom
feat/332-finish-auth
May 27, 2026
Merged

feat/332 finish auth#333
krisarmstrong merged 1 commit into
mainfrom
feat/332-finish-auth

Conversation

@krisarmstrong

Copy link
Copy Markdown
Collaborator

@qodo-code-review

Copy link
Copy Markdown

Qodo reviews are paused for this user.

Troubleshooting steps vary by plan Learn more →

On a Teams plan?
Reviews resume once this user has a paid seat and their Git account is linked in Qodo.
Link Git account →

Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center?
These require an Enterprise plan - Contact us
Contact us →

@krisarmstrong
krisarmstrong enabled auto-merge (squash) May 27, 2026 15:02
… + Setup (#332)

Final sweep completes the forms-stack migration started in stems #328
(foundation + Y.1564 pilot), #330 (6 ConfigForms), and #331 (MFA
setup + disable modals). All 13 forms in stem are now on
react-hook-form + valibot.

Migrations
- App.tsx login form — username + password, uses LoginSchema
- App.tsx MFA verify form — 6-digit code, uses MfaVerifySchema
- components/recovery/RecoveryForm.tsx — token + new password +
  confirm, uses new RecoveryCompleteSchema (cross-field check for
  password == confirmPassword). PasswordField sub-component refactored
  to accept UseFormRegisterReturn so register('password') threads
  through in one line.
- components/setup/SetupWizard.tsx — password + confirm (username is
  fixed from setup-status prop, not user-edited). Uses revised
  SetupWizardSchema (drops the username field that the form doesn't
  actually accept user input for; the v.check() cross-field rule
  remains).

Schema additions
- RecoveryCompleteSchema in src/schemas/auth.ts. The recovery-token
  flow is distinct from the recovery-code flow (RecoveryEnterSchema
  for the latter, which is still defined but not yet wired — that's
  for a future entry-by-code flow).

Out of scope
- The hand-rolled `passwordValid` / `passwordsMatch` derived state in
  the old RecoveryForm is gone — react-hook-form's formState.isValid
  now drives the submit button. The submit handler no longer
  re-validates because the resolver already gated it.

Closes #332.
@github-actions

Copy link
Copy Markdown
Contributor

License Compliance Report

All dependencies pass license compliance checks

Go Dependencies

  • Unknown: 31 package(s)
  • MIT: 26 package(s)
  • BSD-3-Clause: 16 package(s)
  • Apache-2.0: 11 package(s)
  • BSD-2-Clause: 1 package(s)

npm Dependencies

See full report in workflow artifacts

Allowed Licenses: MIT, Apache-2.0, BSD-*, ISC, CC0-1.0, MPL-2.0
Forbidden: GPL, AGPL, SSPL (strong copyleft)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant