Skip to content

feat: change-password form on /account.html (climb to rung 2) - #17

Merged
melvincarvalho merged 1 commit into
gh-pagesfrom
feat-change-password
May 16, 2026
Merged

melvincarvalho merged 1 commit into
gh-pagesfrom
feat-change-password

Conversation

@melvincarvalho

Copy link
Copy Markdown
Contributor

Summary

Closes the climb path from rung 1 (me/me) to rung 2 (your own password) introduced in issue #6.

Adds a Password section to the account dashboard. Click "Change password" → reveals form (Current / New / Confirm) → submit POSTs JSON {currentPassword, newPassword} to JSS's PUT /idp/credentials via session.authFetch (DPoP-bound). On success: green "Password updated. You're on rung 2 now." JSS persists the new password; old me no longer authenticates.

Browser save-password integration

Form follows the standard documented pattern for change-password forms:

  • Hidden <input autocomplete="username" value="me"> so the saved credential gets tagged with username me
  • Visible <input autocomplete="current-password">
  • Two <input autocomplete="new-password"> (new + confirm)

Chrome: prompts "Update password?" with Username me populated. ✓
Brave: stricter password-manager heuristics on http://localhost; doesn't always prompt. Known browser quirk, not a markup issue.

Also in this PR (small)

  • Explore row reorder: /public/ first, then profile
  • "Profile" → "profile" (lowercase, matches URL-shaped siblings)

Test plan

  • Sign in with me/me → /account.html
  • Change password form: wrong current → 401 surfaced
  • Mismatched new/confirm → inline error
  • Valid submission → 204 + green success
  • Sign out, sign back in: old me fails, new password works (verified by user)
  • Chrome: save-password prompt appears with me username

Refs #1 #6

Adds a Password section to the account dashboard. Reveal-on-click
form (current / new / confirm) that POSTs to JSS's PUT
/idp/credentials via session.authFetch (DPoP-bound bearer). On
success, shows "Password updated. You're on rung 2 now." Closes
the climb path from issue #6's auth ladder.

Form markup follows the documented standard for change-password
forms (hidden username input with autocomplete="username", visible
current-password + two new-password inputs). Chrome offers to save
"me / <new password>" as a credential. Brave's password manager
has stricter heuristics and may not prompt on http://localhost —
known browser quirk, not a markup issue.

Also tidies the Explore row on the dashboard:
- swap /public/ and profile (now /public/ first)
- lowercase "profile" (matches the URL-shaped sibling buttons)

Bumps jspod to 0.0.19.

Refs #1 #6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant