fix: add the missing /verify-email page
Verification emails linked to /verify-email?token=..., but no such route existed in main.tsx and nothing in the frontend ever called POST /api/customers/verify-email. The SPA catch-all served index.html, no route matched, and the page rendered blank -- so the token was never redeemed and accounts stayed unverified forever. The gap was invisible until SMTP was configured, because no verification email had ever actually been delivered. Adds VerifyEmail.tsx (verifying / verified / failed states), a verifyEmail call in customerApi, and the route. The request is pinned to a single firing via a ref: the endpoint deletes the token on success, so StrictMode's double effect invocation in dev would otherwise overwrite the success state with "invalid or expired token". Verified end to end against a local stack: a real token flips customers.email_verified to true and is consumed from customer_tokens. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -40,6 +40,14 @@ export function loginCustomer(email: string, password: string): Promise<Customer
|
||||
}).then(res => handle<Customer>(res));
|
||||
}
|
||||
|
||||
export function verifyEmail(token: string): Promise<{ status: string }> {
|
||||
return fetch('/api/customers/verify-email', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ token })
|
||||
}).then(res => handle<{ status: string }>(res));
|
||||
}
|
||||
|
||||
export function logoutCustomer(): Promise<void> {
|
||||
return fetch('/api/customers/logout', { method: 'POST' }).then(() => undefined);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user