feat(users): support creating app users with a Firebase Auth account

New users can now be created with a password, which creates a real
Firebase Auth account (so they can log into the mobile app immediately)
alongside the Firestore profile document. UserCreate is now
UserProfile + password (request-only, never persisted or echoed back);
deleting a user also removes their Auth account.

- backend/users: split UserCreate into UserProfile (persisted shape)
  and UserCreate (adds password), wire firebase_auth create/delete
- CreateUserModal: new lightweight modal for creating a user from
  other flows (e.g. device onboarding) without leaving the page
- UserForm: adds the password field for new users; also fixes
  useToast() being used undestructured (toast.success(...) was being
  called on the hook's return value instead of its .toast method)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-21 18:31:37 +03:00
co-authored by Claude Sonnet 5
parent 6e0a291228
commit 0d79a9f72c
4 changed files with 147 additions and 10 deletions
+6 -2
View File
@@ -4,7 +4,7 @@ from typing import List, Optional
# --- Request / Response schemas ---
class UserCreate(BaseModel):
class UserProfile(BaseModel):
email: str = ""
display_name: str = ""
photo_url: str = ""
@@ -17,6 +17,10 @@ class UserCreate(BaseModel):
quickSettingsPIN: str = ""
class UserCreate(UserProfile):
password: str = "" # request-only — used to create the Firebase Auth account, never persisted to Firestore or echoed back
class UserUpdate(BaseModel):
email: Optional[str] = None
display_name: Optional[str] = None
@@ -29,7 +33,7 @@ class UserUpdate(BaseModel):
quickSettingsPIN: Optional[str] = None
class UserInDB(UserCreate):
class UserInDB(UserProfile):
id: str
created_time: str = ""
lastActive: str = ""