Search by

componenta / auth-magic-link

Shelamkoff

Pre-auth-bound magic-link authentication for Componenta Auth 3

Package info

github.com/componenta/auth-magic-link

pkg:composer/componenta/auth-magic-link

Statistics

Installs: 2

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

v1.0.0 2026-09-27 22:33 UTC

This package is auto-updated.

Last update: 2026-09-27 22:46:43 UTC


README

Magic-link authentication for Componenta Auth 3.

The default browser profile is same-browser only. Requesting a link creates a short-lived pre-authentication transaction. The delivery adapter must put both the opaque one-time token and the public pre-auth transaction UUID (binding) into the link.

The landing page POSTs both values to the verify endpoint while the browser also presents the HttpOnly pre-auth cookie and memory-held request token. The binding UUID must match that exact browser transaction before the one-time token is consumed. This prevents login-CSRF/session-swapping and intentionally does not model cross-device magic links.

One-time bearer persistence is delegated to componenta/auth-token.

Magic-link evidence is intentionally classified as one_time_link, not as a generic possession factor and not as phishing resistant. In particular, an email-delivered link must not accidentally satisfy an assurance policy that expects a cryptographic possession authenticator.