Skip to content

feat(config): add phishing_resistant_only system config key - #89

Merged
Bccorb merged 1 commit into
mainfrom
feat/phishing-resistant-only
Oct 6, 2026
Merged

Bccorb merged 1 commit into
mainfrom
feat/phishing-resistant-only

Conversation

@Bccorb

@Bccorb Bccorb commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Refs fells-code/seamless-auth-api#177.

Adds phishing_resistant_only (boolean, default false) to SystemConfigSchema and SystemConfigPatchSchema. The API enforces it in a follow-up PR. When it is on, the only way to start a session is a passkey. Email and phone codes, magic links, TOTP and OAuth are refused, whatever login_methods says, with one exception: a code is accepted once to verify a new account's address before its first passkey is enrolled.

Defaults to off, so existing deployments parse and behave as before. Minor bump.

Verified with lint, typecheck, format check, tests (278 passed) and build.

@Bccorb
Bccorb merged commit d34c2ef into main Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant