feat: real phone OTP verification (Twilio) in register + onboarding #16

Merged
tanweer919 merged 1 commits from tanweer919/lynkeduppro-crm:feat/login-methods into goutamnextflow 2026-07-12 22:59:23 +00:00
3 changed files with 125 additions and 100 deletions
Showing only changes of commit da7f7a7891 - Show all commits
+4 -4
View File
@@ -8,7 +8,7 @@
"name": "lynkeduppro-crm", "name": "lynkeduppro-crm",
"version": "0.1.0", "version": "0.1.0",
"dependencies": { "dependencies": {
"@abe-kap/appshell-sdk": "^0.2.5", "@abe-kap/appshell-sdk": "^0.2.6",
"clsx": "^2.1.1", "clsx": "^2.1.1",
"lucide-react": "^1.21.0", "lucide-react": "^1.21.0",
"next": "16.2.9", "next": "16.2.9",
@@ -28,9 +28,9 @@
} }
}, },
"node_modules/@abe-kap/appshell-sdk": { "node_modules/@abe-kap/appshell-sdk": {
"version": "0.2.5", "version": "0.2.6",
"resolved": "https://npm.pkg.github.com/download/@abe-kap/appshell-sdk/0.2.5/76bddffe21164d833c4a63adbb6409930dbc1356", "resolved": "https://npm.pkg.github.com/download/@abe-kap/appshell-sdk/0.2.6/d47293556f910a31ed189bbabab4c81022549744",
"integrity": "sha512-iHkdtkUs+sgiEY+2xbQDlm9WOtEbrbB0Z/YoiBZrXM64PT4+gcgFf3RPpKNSqqkVT6LzoL2mZjulFpSMCLw+fA==", "integrity": "sha512-OAMY3Lhahdl8lSvsNT5uBZFZVeV2Nr0E/QDIqWErZj8Q4jbysHLNnF0/ra/yrmNfVSZg3wPtV5OADVG67r6jqA==",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@supabase/supabase-js": "^2.108.2", "@supabase/supabase-js": "^2.108.2",
+1 -1
View File
@@ -9,7 +9,7 @@
"lint": "eslint" "lint": "eslint"
}, },
"dependencies": { "dependencies": {
"@abe-kap/appshell-sdk": "^0.2.5", "@abe-kap/appshell-sdk": "^0.2.6",
"clsx": "^2.1.1", "clsx": "^2.1.1",
"lucide-react": "^1.21.0", "lucide-react": "^1.21.0",
"next": "16.2.9", "next": "16.2.9",
+120 -95
View File
@@ -25,10 +25,14 @@ export function RegisterFlow({ mode = "register" }: { mode?: "register" | "onboa
// we only SET a password + persist the profile, and the OTP-verify step is skipped. // we only SET a password + persist the profile, and the OTP-verify step is skipped.
const onboard = mode === "onboard"; const onboard = mode === "onboard";
const router = useRouter(); const router = useRouter();
const { register, setPassword, getUserEmail } = useAuth(); const { register, setPassword, getUserEmail, addPhone, verifyPhone } = useAuth();
const { sdk } = useAppShell(); const { sdk } = useAppShell();
const [step, setStep] = useState(0); const [step, setStep] = useState(0);
const [submitErr, setSubmitErr] = useState(""); const [submitErr, setSubmitErr] = useState("");
// Verifying a phone via Supabase needs a live session. Onboarding already has one
// (Google OAuth); registration creates the account when leaving the Account step,
// then attaches + verifies the phone on it. `creating` guards the Account button.
const [creating, setCreating] = useState(false);
// address (lifted from StepAddress/AddressBlock so finish() can persist it) // address (lifted from StepAddress/AddressBlock so finish() can persist it)
const [regAddr, setRegAddr] = useState<Addr>({}); const [regAddr, setRegAddr] = useState<Addr>({});
@@ -50,8 +54,7 @@ export function RegisterFlow({ mode = "register" }: { mode?: "register" | "onboa
const [termsOk, setTermsOk] = useState(false); const [termsOk, setTermsOk] = useState(false);
const [privacyOk, setPrivacyOk] = useState(false); const [privacyOk, setPrivacyOk] = useState(false);
// verify step // verify step (email is trusted without an OTP — see verifyValid below)
const [emailVerified, setEmailVerified] = useState(false);
const [phoneVerified, setPhoneVerified] = useState(false); const [phoneVerified, setPhoneVerified] = useState(false);
// Onboarding: prefill the verified email — from the session-storage hint the login // Onboarding: prefill the verified email — from the session-storage hint the login
@@ -63,7 +66,7 @@ export function RegisterFlow({ mode = "register" }: { mode?: "register" | "onboa
// eslint-disable-next-line react-hooks/exhaustive-deps // eslint-disable-next-line react-hooks/exhaustive-deps
}, [onboard]); }, [onboard]);
const STEP_LABELS = onboard ? ["Profile", "Address"] : STEPS; const STEP_LABELS = onboard ? ["Profile", "Verify", "Address"] : STEPS;
const isSelf = relationship === "Customer" || relationship === "Owner"; const isSelf = relationship === "Customer" || relationship === "Owner";
const isEmployee = relationship === "Employee"; const isEmployee = relationship === "Employee";
@@ -76,7 +79,26 @@ export function RegisterFlow({ mode = "register" }: { mode?: "register" | "onboa
first.trim() && last.trim() && EMAIL_RE.test(sso?.email || email) && phoneOk && pwOk && first.trim() && last.trim() && EMAIL_RE.test(sso?.email || email) && phoneOk && pwOk &&
termsOk && privacyOk && (isSelf || (alloeIdOk && (isEmployee || (alloeFirst.trim() && alloeLast.trim())))); termsOk && privacyOk && (isSelf || (alloeIdOk && (isEmployee || (alloeFirst.trim() && alloeLast.trim()))));
const step2Valid = emailVerified && phoneVerified; // Email is already trusted in both flows (registration: Supabase auto-confirms on
// signup; onboarding: Google-verified), so the Verify step only gates on the phone.
const verifyValid = phoneVerified;
// Registration: create the auth account when leaving the Account step, so the phone
// can be attached + verified against a live session at the Verify step. Onboarding
// is already authenticated, so it just advances.
async function leaveAccountStep() {
if (onboard || !isShellConfigured() || sso) { setStep(1); return; }
setSubmitErr("");
setCreating(true);
try {
await register(email, pw);
setStep(1);
} catch {
setSubmitErr("We couldn't create that account. The email may already be registered.");
} finally {
setCreating(false);
}
}
async function finish() { async function finish() {
const finalEmail = sso?.email || email; const finalEmail = sso?.email || email;
@@ -91,13 +113,12 @@ export function RegisterFlow({ mode = "register" }: { mode?: "register" | "onboa
if (isShellConfigured()) { if (isShellConfigured()) {
setSubmitErr(""); setSubmitErr("");
// 1) Auth account. Onboarding users are already authenticated via Google — set // 1) Auth account already exists at this point — registration created it when
// a password so email+password login works too. Everyone else registers now. // leaving the Account step; onboarding users signed in via Google. Onboarding
if (onboard) { // additionally sets a password so email+password login works too (the phone was
try { if (pw) await setPassword(pw); } catch { /* non-fatal — the profile still saves */ } // just verified against the same live session).
} else if (!sso) { if (onboard && pw) {
try { await register(finalEmail, pw); } try { await setPassword(pw); } catch { /* non-fatal — the profile still saves */ }
catch { setSubmitErr("We couldn't create that account. The email may already be registered."); return; }
} }
// 2) Persist the full CRM registration payload to be-crm (name, phone, persona, // 2) Persist the full CRM registration payload to be-crm (name, phone, persona,
// allottee, both addresses, consent). Non-fatal: the auth account exists either way. // allottee, both addresses, consent). Non-fatal: the auth account exists either way.
@@ -130,34 +151,36 @@ export function RegisterFlow({ mode = "register" }: { mode?: "register" | "onboa
<Stepper current={step} labels={STEP_LABELS} /> <Stepper current={step} labels={STEP_LABELS} />
{step === 0 && ( {step === 0 && (
<StepAccount
onboard={onboard}
sso={sso} setSso={setSso} email={email} setEmail={setEmail}
first={first} setFirst={setFirst} last={last} setLast={setLast}
cc={cc} setCc={setCc} phone={phone} setPhone={setPhone} phoneOk={phoneOk} country={country}
pw={pw} setPw={setPw}
relationship={relationship} setRelationship={setRelationship} isSelf={isSelf}
alloeNo={alloeNo} setAlloeNo={setAlloeNo} alloeIdOk={alloeIdOk}
alloeFirst={alloeFirst} setAlloeFirst={setAlloeFirst} alloeLast={alloeLast} setAlloeLast={setAlloeLast}
termsOk={termsOk} setTermsOk={setTermsOk} privacyOk={privacyOk} setPrivacyOk={setPrivacyOk}
valid={!!step0Valid}
onContinue={() => setStep(1)} toLogin={() => router.push("/portal/login")}
/>
)}
{step === 1 && !onboard && (
<StepVerify
emailValue={sso?.email || email} cc={cc} phone={phone} country={country}
emailVerified={emailVerified} setEmailVerified={setEmailVerified}
phoneVerified={phoneVerified} setPhoneVerified={setPhoneVerified}
valid={step2Valid} onBack={() => setStep(0)} onContinue={() => setStep(2)}
/>
)}
{((onboard && step === 1) || (!onboard && step === 2)) && (
<> <>
{submitErr && <div style={{ marginBottom: 14 }}><FlashNote tone="error">{submitErr}</FlashNote></div>} {submitErr && <div style={{ marginBottom: 14 }}><FlashNote tone="error">{submitErr}</FlashNote></div>}
<StepAddress sameAs={mailingSame} setSameAs={setMailingSame} onRegAddr={setRegAddr} onMailAddr={setMailAddr} onBack={() => setStep(onboard ? 0 : 1)} onFinish={finish} /> <StepAccount
onboard={onboard} creating={creating}
sso={sso} setSso={setSso} email={email} setEmail={setEmail}
first={first} setFirst={setFirst} last={last} setLast={setLast}
cc={cc} setCc={setCc} phone={phone} setPhone={setPhone} phoneOk={phoneOk} country={country}
pw={pw} setPw={setPw}
relationship={relationship} setRelationship={setRelationship} isSelf={isSelf}
alloeNo={alloeNo} setAlloeNo={setAlloeNo} alloeIdOk={alloeIdOk}
alloeFirst={alloeFirst} setAlloeFirst={setAlloeFirst} alloeLast={alloeLast} setAlloeLast={setAlloeLast}
termsOk={termsOk} setTermsOk={setTermsOk} privacyOk={privacyOk} setPrivacyOk={setPrivacyOk}
valid={!!step0Valid}
onContinue={leaveAccountStep} toLogin={() => router.push("/portal/login")}
/>
</>
)}
{step === 1 && (
<StepVerify
cc={cc} phone={phone} country={country}
phoneVerified={phoneVerified} setPhoneVerified={setPhoneVerified}
valid={verifyValid} onBack={() => setStep(0)} onContinue={() => setStep(2)}
/>
)}
{step === 2 && (
<>
{submitErr && <div style={{ marginBottom: 14 }}><FlashNote tone="error">{submitErr}</FlashNote></div>}
<StepAddress sameAs={mailingSame} setSameAs={setMailingSame} onRegAddr={setRegAddr} onMailAddr={setMailAddr} onBack={() => setStep(1)} onFinish={finish} />
</> </>
)} )}
</div> </div>
@@ -175,7 +198,7 @@ function StepAccount(p: {
alloeNo: string; setAlloeNo: (v: string) => void; alloeIdOk: boolean; alloeNo: string; setAlloeNo: (v: string) => void; alloeIdOk: boolean;
alloeFirst: string; setAlloeFirst: (v: string) => void; alloeLast: string; setAlloeLast: (v: string) => void; alloeFirst: string; setAlloeFirst: (v: string) => void; alloeLast: string; setAlloeLast: (v: string) => void;
termsOk: boolean; setTermsOk: (v: boolean) => void; privacyOk: boolean; setPrivacyOk: (v: boolean) => void; termsOk: boolean; setTermsOk: (v: boolean) => void; privacyOk: boolean; setPrivacyOk: (v: boolean) => void;
valid: boolean; onContinue: () => void; toLogin: () => void; onboard?: boolean; valid: boolean; onContinue: () => void; toLogin: () => void; onboard?: boolean; creating?: boolean;
}) { }) {
// Onboarding (OAuth) starts on the profile step — email is already known + verified. // Onboarding (OAuth) starts on the profile step — email is already known + verified.
const [phase, setPhase] = useState<"sso" | "profile">(p.onboard ? "profile" : "sso"); const [phase, setPhase] = useState<"sso" | "profile">(p.onboard ? "profile" : "sso");
@@ -313,7 +336,9 @@ function StepAccount(p: {
{!p.valid && <p className="hint-line">Fill all required fields and accept both documents to continue.</p>} {!p.valid && <p className="hint-line">Fill all required fields and accept both documents to continue.</p>}
<button className="btn btn-primary" style={{ marginTop: 14 }} disabled={!p.valid} onClick={p.onContinue}>{p.onboard ? "Continue" : "Create Account & Verify"} <Icon name="arrowR" size={16} /></button> <button className="btn btn-primary" style={{ marginTop: 14 }} disabled={!p.valid || p.creating} onClick={p.onContinue}>
{p.creating ? "Creating account…" : p.onboard ? "Continue" : "Create Account & Verify"} {!p.creating && <Icon name="arrowR" size={16} />}
</button>
{modal === "terms" && <LegalModal doc={TERMS} onClose={() => setModal(null)} onReviewed={() => { reviewed.terms = true; setModal(null); }} />} {modal === "terms" && <LegalModal doc={TERMS} onClose={() => setModal(null)} onReviewed={() => { reviewed.terms = true; setModal(null); }} />}
{modal === "privacy" && <LegalModal doc={PRIVACY} onClose={() => setModal(null)} onReviewed={() => { reviewed.privacy = true; setModal(null); }} />} {modal === "privacy" && <LegalModal doc={PRIVACY} onClose={() => setModal(null)} onReviewed={() => { reviewed.privacy = true; setModal(null); }} />}
@@ -323,10 +348,13 @@ function StepAccount(p: {
// module-level reviewed flags (per mount lifetime) — enables the checkboxes after a doc is read // module-level reviewed flags (per mount lifetime) — enables the checkboxes after a doc is read
const reviewed = { terms: false, privacy: false }; const reviewed = { terms: false, privacy: false };
/* ====================== STEP 1 — VERIFY ====================== */ /* ====================== STEP 1 VERIFY PHONE ======================
Email is already trusted (registration: Supabase auto-confirms on signup;
onboarding: Google-verified), so this step only verifies the phone via a real
SMS OTP: addPhone() Twilio texts a code verifyPhone() confirms it. Both
run against the live Supabase session established in the previous step. */
function StepVerify(p: { function StepVerify(p: {
emailValue: string; cc: string; phone: string; country: typeof countryCodes[number]; cc: string; phone: string; country: typeof countryCodes[number];
emailVerified: boolean; setEmailVerified: (v: boolean) => void;
phoneVerified: boolean; setPhoneVerified: (v: boolean) => void; phoneVerified: boolean; setPhoneVerified: (v: boolean) => void;
valid: boolean; onBack: () => void; onContinue: () => void; valid: boolean; onBack: () => void; onContinue: () => void;
}) { }) {
@@ -334,12 +362,11 @@ function StepVerify(p: {
return ( return (
<div> <div>
<StepBack onClick={p.onBack} /> <StepBack onClick={p.onBack} />
<h1>Verify email &amp; phone</h1> <h1>Verify your phone</h1>
<p className="sub">Confirm both so we can secure your account.</p> <p className="sub">We&apos;ll text a one-time code to confirm your number. Your email is already verified.</p>
<div className="col gap-4" style={{ marginTop: 16 }}> <div className="col gap-4" style={{ marginTop: 16 }}>
<VerifyChannel kind="email" initial={p.emailValue} country={p.country} cc={p.cc} initialPhone={p.phone} verified={p.emailVerified} onVerified={() => p.setEmailVerified(true)} /> <PhoneVerify cc={p.cc} country={p.country} initialPhone={p.phone} verified={p.phoneVerified} onVerified={() => p.setPhoneVerified(true)} />
<VerifyChannel kind="phone" initial={p.emailValue} country={p.country} cc={p.cc} initialPhone={p.phone} verified={p.phoneVerified} onVerified={() => p.setPhoneVerified(true)} />
</div> </div>
<div style={{ marginTop: 14 }}><RememberDevice checked={remember} onChange={setRemember} /></div> <div style={{ marginTop: 14 }}><RememberDevice checked={remember} onChange={setRemember} /></div>
@@ -348,40 +375,47 @@ function StepVerify(p: {
); );
} }
type SendState = "idle" | "sending" | "ok" | "invalid_email" | "mailbox_full" | "bounce_risk" | "invalid_mobile"; type SendState = "idle" | "sending" | "sent" | "invalid_mobile" | "send_error";
function VerifyChannel({ kind, initial, country, cc, initialPhone, verified, onVerified }: { function PhoneVerify({ cc, country, initialPhone, verified, onVerified }: {
kind: "email" | "phone"; initial: string; country: typeof countryCodes[number]; cc: string; initialPhone: string; cc: string; country: typeof countryCodes[number]; initialPhone: string;
verified: boolean; onVerified: () => void; verified: boolean; onVerified: () => void;
}) { }) {
const [value, setValue] = useState(kind === "email" ? initial : initialPhone); const { addPhone, verifyPhone } = useAuth();
const [via, setVia] = useState<"primary" | "wa">("primary"); const [value, setValue] = useState(initialPhone);
const [state, setState] = useState<SendState>("idle"); const [state, setState] = useState<SendState>("idle");
const [otpError, setOtpError] = useState(false); const [otpError, setOtpError] = useState("");
const primaryLabel = kind === "email" ? "Email" : "SMS"; const e164 = `${cc}${value.replace(/\D/g, "")}`;
function send() { async function send() {
if (value.replace(/\D/g, "").length !== country.digits) { setState("invalid_mobile"); return; }
setState("sending"); setState("sending");
setTimeout(() => { setOtpError("");
if (kind === "email") { try {
if (!EMAIL_RE.test(value)) return setState("invalid_email"); await addPhone(e164); // Supabase → Twilio sends the SMS OTP
if (value.includes("full")) return setState("mailbox_full"); setState("sent");
if (value.includes("bo")) return setState("bounce_risk"); } catch {
return setState("ok"); setState("send_error");
} else { }
if (value.replace(/\D/g, "").length !== country.digits) return setState("invalid_mobile"); }
return setState("ok");
} async function submit(code: string) {
}, 700); setOtpError("");
try {
await verifyPhone(e164, code); // confirm the OTP (phone_change)
onVerified();
} catch {
setOtpError("That code didn't match. Check the SMS and try again.");
}
} }
if (verified) { if (verified) {
return ( return (
<div className="vchannel verified"> <div className="vchannel verified">
<div className="row between"> <div className="row between">
<span className="row gap-2" style={{ fontWeight: 600, fontSize: 14 }}><Icon name={kind === "email" ? "mail" : "phone"} size={16} /> {kind === "email" ? "Email" : "Mobile"}</span> <span className="row gap-2" style={{ fontWeight: 600, fontSize: 14 }}><Icon name="phone" size={16} /> Mobile</span>
<Badge tone="green"><Icon name="check" size={12} /> Verified</Badge> <Badge tone="green"><Icon name="check" size={12} /> Verified</Badge>
</div> </div>
<p className="faint" style={{ fontSize: 12.5, marginTop: 8 }}>{kind === "email" ? value : `${cc} ${value}`}</p> <p className="faint" style={{ fontSize: 12.5, marginTop: 8 }}>{cc} {value}</p>
</div> </div>
); );
} }
@@ -389,43 +423,34 @@ function VerifyChannel({ kind, initial, country, cc, initialPhone, verified, onV
return ( return (
<div className="vchannel"> <div className="vchannel">
<div className="row between" style={{ marginBottom: 12 }}> <div className="row between" style={{ marginBottom: 12 }}>
<span className="row gap-2" style={{ fontWeight: 600, fontSize: 14 }}><Icon name={kind === "email" ? "mail" : "phone"} size={16} /> {kind === "email" ? "Email address" : "Mobile number"}</span> <span className="row gap-2" style={{ fontWeight: 600, fontSize: 14 }}><Icon name="phone" size={16} /> Mobile number</span>
</div> </div>
{kind === "email" ? ( <div className="phone-row">
<input className="input" value={value} onChange={(e) => { setValue(e.target.value); setState("idle"); }} placeholder="you@example.com" /> <span className="input cc-select" style={{ display: "flex", alignItems: "center", justifyContent: "center", gap: 7 }}>
) : ( {/* eslint-disable-next-line @next/next/no-img-element */}
<div className="phone-row"> <img className="cc-flag-img static" src={flagUrl(country.flag)} alt={country.name} width={22} height={16} />
<span className="input cc-select" style={{ display: "flex", alignItems: "center", justifyContent: "center", gap: 7 }}> {cc}
{/* eslint-disable-next-line @next/next/no-img-element */} </span>
<img className="cc-flag-img static" src={flagUrl(country.flag)} alt={country.name} width={22} height={16} /> <input className="input grow" inputMode="numeric" value={value} disabled={state === "sent"} onChange={(e) => { setValue(e.target.value.replace(/\D/g, "")); setState("idle"); }} placeholder={country.example} />
{cc} </div>
</span>
<input className="input grow" inputMode="numeric" value={value} onChange={(e) => { setValue(e.target.value.replace(/\D/g, "")); setState("idle"); }} placeholder={country.example} />
</div>
)}
<div className="row between" style={{ marginTop: 12 }}> <div className="row between" style={{ marginTop: 12 }}>
<div className="seg"> <span className="faint" style={{ fontSize: 12 }}>Standard SMS rates may apply.</span>
<button className={via === "primary" ? "on" : ""} onClick={() => setVia("primary")}>{primaryLabel}</button> <button className="btn btn-sm" style={{ width: "auto" }} disabled={state === "sending" || state === "sent"} onClick={send}>
<button className={via === "wa" ? "on" : ""} onClick={() => setVia("wa")}><Icon name="whatsapp" size={14} /> WhatsApp</button> {state === "sending" ? "Sending…" : state === "sent" ? "Sent" : "Send code"}
</div>
<button className="btn btn-sm" style={{ width: "auto" }} disabled={state === "sending" || state === "ok"} onClick={send}>
{state === "sending" ? "Sending…" : "Send code"}
</button> </button>
</div> </div>
{state === "ok" && <p className="faint" style={{ fontSize: 12, marginTop: 10 }}>OTP sent via {via === "wa" ? "WhatsApp" : primaryLabel}.</p>} {state === "sent" && <p className="faint" style={{ fontSize: 12, marginTop: 10 }}>Code sent to {cc} {value} by SMS.</p>}
{state === "invalid_email" && <div style={{ marginTop: 10 }}><FlashNote tone="error">That email address looks invalid.</FlashNote></div>}
{state === "mailbox_full" && <div style={{ marginTop: 10 }}><FlashNote tone="warn">This mailbox appears full try another email.</FlashNote></div>}
{state === "bounce_risk" && <div style={{ marginTop: 10 }}><FlashNote tone="warn">High bounce risk for this address.</FlashNote></div>}
{state === "invalid_mobile" && <div style={{ marginTop: 10 }}><FlashNote tone="error">Enter a valid {country.digits}-digit mobile number.</FlashNote></div>} {state === "invalid_mobile" && <div style={{ marginTop: 10 }}><FlashNote tone="error">Enter a valid {country.digits}-digit mobile number.</FlashNote></div>}
{state === "send_error" && <div style={{ marginTop: 10 }}><FlashNote tone="error">Couldn&apos;t send the code. Check the number and try again.</FlashNote></div>}
{state === "ok" && ( {state === "sent" && (
<div style={{ marginTop: 14 }}> <div style={{ marginTop: 14 }}>
<OtpBoxes onComplete={(c) => { if (c === "000000") setOtpError(true); else { setOtpError(false); onVerified(); } }} error={otpError} /> <OtpBoxes onComplete={submit} error={!!otpError} />
{otpError && <div style={{ marginTop: 10 }}><FlashNote tone="error">Incorrect code.</FlashNote></div>} {otpError && <div style={{ marginTop: 10 }}><FlashNote tone="error">{otpError}</FlashNote></div>}
<div style={{ marginTop: 12 }}><ResendLink seconds={60} /></div> <div style={{ marginTop: 12 }}><ResendLink seconds={60} onResend={send} /></div>
</div> </div>
)} )}
</div> </div>