Files
pad/web/src/lib/api
xarmian a04091517c feat(web): email verification banner + resend + register success (TASK-1940) (#810)
Wave 5 of PLAN-1933 (DR-1 model b) — surfaces the unverified-email state
in the web UI and makes it actionable.

- AuthSession user type gains `email_verified` (owns the session user-type
  change); register response user type gains it too.
- authStore.emailVerified getter, default TRUE (mirrors `emailConfigured ??
  true`) — a missing field or a self-host instance must never show the
  banner.
- VerifyEmailBanner rendered in the workspace layout above ConnectBanner,
  shown only when `cloudMode && user && !emailVerified`, with a Resend
  button hitting POST /auth/resend-verification and a "sent" confirmation
  (enumeration-safe, always 200).
- api.auth.resendVerification client method.
- /register shows a "check your email to verify your account" state after a
  cloud self-serve signup returns an unverified user, instead of navigating
  in and implying full access; includes resend + continue actions.

Gates: make check (lint + go test + govulncheck + web-check) green;
cd web && npm run check → 0 errors.

Claude-Session: https://claude.ai/code/session_01HxBkAMiFBtCRJ2tKSCt3ST
2026-07-04 04:15:46 -04:00
..