a005adb1

Author: Michael Lynch <git@mtlynch.io>

Committer: Michael Lynch <mtlynch@noreply.codeberg.org>

Make dev/prod login branching explicit, fix prod token leak (#199)

loginPost overloaded a single token-presence check to encode two unrelated
decisions: whether the email was registered, and whether to redirect to the
magic link (dev) or email it (prod). Because both dev and prod token creators
return a real token for registered users, prod fell into the redirect branch,
leaking the login token in the URL and bypassing email entirely.

Separate the two decisions:
- Handle ErrUnregisteredEmail explicitly by rendering the same confirmation
  page as a successful send, instead of subtly zeroing the entry.
- Gate the dev "redirect to magic link" behavior on an explicit build-tagged
  skipLoginEmail flag plumbed through ServerParams, so prod never redirects to
  the token.

Add TestLoginPostDoesNotLeakTokenInProdMode as a regression test.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

Reviewed-on: https://codeberg.org/mtlynch/little-moments/pulls/199

Suite timing

Time to Start Worker time Duration Time to finish Idle
Config 1s 8s 8s 10s 1s
Eval 8s 35s 35s 43s 0s
Build 15s 1m08s 16s 31s 0s
Suite 1s 1m52s 41s 43s 1s

Timeline

0s10s20s30s40s