fix(signin): key the resend cooldown to the address it was set for (#20)
The email-step Send button disabled on any running cooldown, so a merchant who mistyped their address was locked out of sending to the corrected one for the rest of the 60s window — a guard the server never had: request_code enforces the cooldown per address (SD-0001 INV-3 -> PUC-2c). Track which address the running cooldown belongs to (cooldownFor) and gate the email-step button through cooldownAppliesTo(), which blocks only while the countdown runs AND the input normalizes (strip+lowercase, mirroring normalize_email / INV-2) to that address. Same address still shows the honest 'Resend in Ns'; any other address sends immediately. The code-step resend is unchanged. Verified in the live UI (wrong address -> Wrong address? -> corrected address sends at once). package-lock.json: sync recorded version with package.json (0.4.0). Closes #20 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Generated
+2
-2
@@ -1,12 +1,12 @@
|
||||
{
|
||||
"name": "wiggleverse-ecomm-frontend",
|
||||
"version": "0.2.0",
|
||||
"version": "0.4.0",
|
||||
"lockfileVersion": 3,
|
||||
"requires": true,
|
||||
"packages": {
|
||||
"": {
|
||||
"name": "wiggleverse-ecomm-frontend",
|
||||
"version": "0.2.0",
|
||||
"version": "0.4.0",
|
||||
"dependencies": {
|
||||
"react": "^18.3.1",
|
||||
"react-dom": "^18.3.1"
|
||||
|
||||
Reference in New Issue
Block a user