Tokens must be cryptographically random (min 32 bytes)
Links must be single-use
Rate limit to prevent email bombing
HTTPS-only for magic link URLs
Constant-time token comparison
Acceptance Criteria
User can request a magic link by email
Clicking the link authenticates the user and returns a JWT
Expired/used tokens are rejected
Rate limiting prevents abuse
Works with common email providers
## Summary
Implement passwordless authentication via email magic links for the multi-tenant backend.
## Design
- Generate cryptographically secure one-time tokens
- Send magic link emails via configurable SMTP provider
- Token expiration (e.g., 15 minutes)
- Rate limiting on magic link requests
- Token invalidation after use
## Implementation Tasks
- [x] Add magic link token generation and storage
- [x] Implement /auth/login endpoint (accepts email, sends magic link)
- [x] Implement /auth/verify endpoint (validates token, issues JWT)
- [x] Configure SMTP email sending
- [x] Add rate limiting per email address
- [x] Add token expiration and cleanup
## Security Considerations
- Tokens must be cryptographically random (min 32 bytes)
- Links must be single-use
- Rate limit to prevent email bombing
- HTTPS-only for magic link URLs
- Constant-time token comparison
## Acceptance Criteria
- [x] User can request a magic link by email
- [x] Clicking the link authenticates the user and returns a JWT
- [x] Expired/used tokens are rejected
- [x] Rate limiting prevents abuse
- [ ] Works with common email providers
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Implement passwordless authentication via email magic links for the multi-tenant backend.
Design
Implementation Tasks
Security Considerations
Acceptance Criteria
Implement authentication systemto Implement email magic link authentication systemlibretech referenced this issue2026-03-02 15:45:53 +01:00