feat: first-login security setup - recovery key revealed on first sign-in #8
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/e2e-key-onboarding"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
From real-user testing feedback: "on first login the app doesn't show the E2E recovery key at all." The engine (
createFreshCrossSigningIdentity()) and the reveal+copy UI (RecoveryKeyModal) both existed, but nothing ever surfaced them during sign-in — the key was only reachable through a small icon buried in the space rail's settings.What this adds
runPostAuthKeySetup()runs after client boot and opens the newFirstLoginSecurityModalin one of two carefully distinguished modes:verificationStore), or deferring.Test impact
loginAs()(e2e helper) auto-dismisses the modal for the rest of the suite (handleSecuritySetup: falseopts out), so no existing spec needed changes. Newe2e/tests/firstLoginSecurity.spec.tscovers the create path end-to-end: key auto-created and revealed, copied, dismissed — and does not reappear on reload.Gate
build clean, 471 unit tests (+1 skip), oxlint 0 errors, full Playwright e2e 14/14 green (13 existing + 1 new). Based on main @
65fdb32.Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com
🤖 Generated with Claude Code
Merged into main at
67f6054(merge commit onto PR #7, which landed first). One real conflict: PLAN.md dev-log entries from PR #7 and PR #8 both appended after the same prior entry - resolved by keeping both entries in sequence (PR #7's entry, then PR #8's). No code conflicts. Gate results on the merged tree: build clean, 471 unit tests passed (1 skipped), lint 0 errors, e2e 15/15 passed (14 prior + firstLoginSecurity.spec.ts). Closing.Pull request closed