authv0.01This module provides authentication and user verification features, including the following:
User Registration
email_tokenUser Login
Two-Factor Authentication
JWT Token Refresh
Logout
Email Verification
Google OAuth Login
Design
Requirements
Tests
Authentication Flows
/core/profileEncryptedSharedPreferences for secure token storageusers table is source of truthdb_generic SeaORM connectoris_rate_limited helper| Endpoint | Cooldown (seconds) |
|---|---|
/api/auth/resend-verification |
60 |
aud matches GOOGLE_CLIENT_ID env var| Field | Type | Purpose |
|---|---|---|
password_hash |
Option<String> |
Set to "GOOGLE_ACCOUNT" placeholder |
email_verified |
bool |
Set to true |
generate_and_dispatch_2faverify_2fa| Field | Type | Purpose |
|---|---|---|
requires_2fa |
bool (optional) |
Enables 2FA login enforcement |
| Method | Path | Description |
|---|---|---|
| POST | /api/auth/register |
Register new user |
| POST | /api/auth/login |
Login with email and password |
| POST | /api/auth/login/google |
Login using Google OAuth |
| POST | /api/auth/verify-email |
Verify email using token |
| POST | /api/auth/resend-verification |
Resend verification email |
| POST | /api/auth/logout |
Logout and blacklist token |
| POST | /api/auth/refresh |
Refresh JWT using existing token |
| POST | /api/auth/verify-2fa |
Verify 2FA code after login attempt |
users| Field | Type | Description |
|---|---|---|
| id | UUID | Primary key |
| name | String (optional) | Display name |
| String | Unique email address | |
| password_hash | Option | Bcrypt hash or placeholder for Google |
| email_verified | bool | Whether email has been verified |
| email_token | Option | Token used for email verification |
| requires_2fa | Option | Whether user requires 2FA |
| created_at | Timestamp | Creation time |
| role | String | User role (e.g. "user", "admin") |
email_verification| Field | Type | Description |
|---|---|---|
id |
UUID | Primary key |
user_id |
UUID | Foreign key to users |
code |
String | Verification token |
expires_at |
DateTimeUtc | When the token expires |
password_reset| Field | Type | Description |
|---|---|---|
id |
UUID | Primary key |
user_id |
UUID | Foreign key to users |
reset_token |
String | Unique reset token |
expires_at |
DateTimeUtc | When the token expires |
two_fa_token| Field | Type | Description |
|---|---|---|
id |
UUID | Primary key |
user_id |
UUID | Foreign key to users |
code |
String | The 2FA code sent (typically 6-digit numeric or alphanumeric) |
temp_token |
String | Temporary session token issued after login, before 2FA success |
expires_at |
DateTimeUtc | Timestamp after which the code becomes invalid |
attempts |
i32 | Tracks how many times user attempted to verify the code |
sent_via |
String | Delivery method, e.g. "email" or "sms" |
created_at |
DateTimeUtc | Timestamp when the token was created |