Add internal grant endpoint + temp-password / force-change flow
- /api/internal/grant: secret-auth endpoint for payment-router to provision access on a paid order — find-or-create user (emailVerified, temp password, mustChangePassword), enroll by course slug list, AccessLog, delivery email. Idempotent by order_id. - User.mustChangePassword flag (+ migration); (student) layout redirects flagged users to /change-password (forced first-login change). - email.ts: sendCourseGrantEmail (temp password for new buyers). - middleware: /api/internal is public (own secret auth). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -18,3 +18,6 @@ TURNSTILE_SECRET_KEY=""
|
||||
|
||||
# Kinescope API
|
||||
KINESCOPE_API_KEY=""
|
||||
|
||||
# Internal access-provisioning (payment-router → /api/internal/grant)
|
||||
INTERNAL_GRANT_SECRET=""
|
||||
|
||||
Reference in New Issue
Block a user