fix(login): back-button nav, single OTP channel, register back buttons
- Login: identify → password/otp now push() history (was replace()), so Back returns to the email screen instead of leaving to /register. - Login: in Shell mode the OTP screen no longer shows an email/SMS toggle — the channel is fixed by how you signed in, so email sign-in never shows a stray SMS option. - Login: hide phone (SMS) sign-in while OTP is mocked — a faked login code can't mint a session (AuthGate would bounce), so it can't work without SMS. Email OTP + password + Google stay real and working. - Register: add Back buttons (email screen → sign in; profile screen → email). - Share MOCK_OTP/DEMO_OTP via @/lib/otp.
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
/**
|
||||
* Demo OTP fallback, shared by the login and registration flows.
|
||||
*
|
||||
* While the Twilio SMS sender is down we can't deliver real one-time codes. When
|
||||
* MOCK_OTP is on, phone verification steps skip Supabase/Twilio and accept a fixed
|
||||
* DEMO_OTP instead. Flip NEXT_PUBLIC_MOCK_OTP to "false" (or remove it) to restore
|
||||
* real SMS — no other change needed.
|
||||
*
|
||||
* IMPORTANT: this only substitutes for a *secondary* verification (e.g. confirming a
|
||||
* phone during registration/onboarding, where the session already exists). It cannot
|
||||
* mock a *login* whose sole credential is the OTP — there the OTP verification is what
|
||||
* mints the session, and a faked code produces no session (the dashboard's AuthGate
|
||||
* would bounce the user straight back). Passwordless login therefore stays real.
|
||||
*/
|
||||
export const MOCK_OTP = process.env.NEXT_PUBLIC_MOCK_OTP === "true";
|
||||
export const DEMO_OTP = "123456";
|
||||
Reference in New Issue
Block a user