feat(users): require password confirmation when creating an app user
Both create paths (Users > Add User page and the CreateUserModal used during device onboarding) now have a Confirm Password field. A mismatch shows an inline error and blocks the create call, so a typo can't silently become the user's Firebase Auth password. The confirm value is client-side only and is never sent to the backend. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -319,6 +319,7 @@ export default function UserForm() {
|
||||
quickSettingsPIN: '',
|
||||
password: '',
|
||||
})
|
||||
const [confirmPassword, setConfirmPassword] = useState('')
|
||||
const [uid, setUid] = useState('')
|
||||
const [loading, setLoading] = useState(false)
|
||||
const [saving, setSaving] = useState(false)
|
||||
@@ -356,6 +357,10 @@ export default function UserForm() {
|
||||
const handleSubmit = async (e) => {
|
||||
e.preventDefault()
|
||||
setError('')
|
||||
if (!isEdit && form.password !== confirmPassword) {
|
||||
setError('Passwords do not match.')
|
||||
return
|
||||
}
|
||||
setSaving(true)
|
||||
try {
|
||||
if (isEdit) {
|
||||
@@ -437,16 +442,28 @@ export default function UserForm() {
|
||||
/>
|
||||
</div>
|
||||
{!isEdit && (
|
||||
<FormField
|
||||
label="Password"
|
||||
name="password"
|
||||
type="password"
|
||||
value={form.password}
|
||||
onChange={set('password')}
|
||||
required
|
||||
placeholder="Min. 6 characters"
|
||||
hint="Used to sign into the mobile app immediately — this creates the Firebase Auth account."
|
||||
/>
|
||||
<div style={{ display: 'grid', gridTemplateColumns: '1fr 1fr', gap: 'var(--space-4)' }}>
|
||||
<FormField
|
||||
label="Password"
|
||||
name="password"
|
||||
type="password"
|
||||
value={form.password}
|
||||
onChange={set('password')}
|
||||
required
|
||||
placeholder="Min. 6 characters"
|
||||
hint="Used to sign into the mobile app immediately — this creates the Firebase Auth account."
|
||||
/>
|
||||
<FormField
|
||||
label="Confirm Password"
|
||||
name="confirm_password"
|
||||
type="password"
|
||||
value={confirmPassword}
|
||||
onChange={(e) => setConfirmPassword(e.target.value)}
|
||||
required
|
||||
placeholder="Re-enter password"
|
||||
error={confirmPassword && form.password !== confirmPassword ? 'Passwords do not match.' : undefined}
|
||||
/>
|
||||
</div>
|
||||
)}
|
||||
<StatusToggle value={form.status} onChange={setVal('status')} />
|
||||
</div>
|
||||
|
||||
Reference in New Issue
Block a user