+ สร้างบัญชีเรียบร้อยแล้ว เพิ่มรูปโปรไฟล์ได้ตามต้องการ หรือกดข้ามเพื่อเริ่มใช้งาน คุณสามารถยืนยันอีเมลภายหลังได้ที่หน้าโปรไฟล์
+
}
รูปโปรไฟล์
@@ -127,9 +133,10 @@ export function ProfileForm({
form="profile-form"
disabled={busy || name.trim().length < 2 || name.trim().length > 80}
>
- {busy ? "กำลังบันทึก..." : "บันทึกโปรไฟล์"}
+ {busy ? "กำลังบันทึก..." : setup ? "บันทึกและเริ่มใช้งาน" : "บันทึกโปรไฟล์"}
- {nextPath && ข้ามและเริ่มใช้งาน}
+ {nextPath && }>ข้ามและเริ่มใช้งาน}
);
diff --git a/components/auth/registration-otp-form.tsx b/components/auth/registration-otp-form.tsx
index 01c1219..85ebfbe 100644
--- a/components/auth/registration-otp-form.tsx
+++ b/components/auth/registration-otp-form.tsx
@@ -33,7 +33,7 @@ export function RegistrationOtpForm({ email, nextPath, setup }: {
try {
const result = await authClient.emailOtp.verifyEmail({ email: address, otp });
if (result.error) throw new Error("รหัสไม่ถูกต้องหรือหมดอายุ กรุณาลองอีกครั้ง");
- const returnPath = setup ? `/profile?setup=1&next=${encodeURIComponent(nextPath)}` : nextPath;
+ const returnPath = setup ? `/auth/register?step=profile&next=${encodeURIComponent(nextPath)}` : nextPath;
router.replace(returnPath);
router.refresh();
} catch (cause) {
diff --git a/lib/auth/server.test.ts b/lib/auth/server.test.ts
index 95ee3d7..90715f4 100644
--- a/lib/auth/server.test.ts
+++ b/lib/auth/server.test.ts
@@ -74,13 +74,21 @@ describe("actual administrator session boundary", () => {
expect(await getCustomerSession()).toMatchObject({ user: { id: "user-1" } });
expect(await getAdminSession()).toMatchObject({ user: { id: "user-1" } });
});
- it("requires verification and sends auth links from the configured sender", async () => {
+ it("allows an unverified customer session but rejects administrator access", async () => {
+ mocks.session.mockResolvedValue({ user: { id: "user-1", email: "a@test.invalid",
+ emailVerified: false, role: "admin" }, session: { id: "guide-session" } });
+ const { getAdminSession, getCustomerSession, requireAdmin } = await import("./server");
+ expect(await getCustomerSession()).toMatchObject({ user: { id: "user-1", emailVerified: false } });
+ expect(await getAdminSession()).toBeNull();
+ await expect(requireAdmin()).rejects.toMatchObject({ status: 401 });
+ });
+ it("allows unverified sign-in and sends auth links from the configured sender", async () => {
testEnv.RESEND_API_KEY = "test-key";
const fetchMock = vi.spyOn(globalThis, "fetch").mockResolvedValue(new Response(null, { status: 200 }));
try {
(await import("./server")).getAuth();
const options = mocks.auth.mock.calls.at(-1)![0];
- expect(options.emailAndPassword.requireEmailVerification).toBe(true);
+ expect(options.emailAndPassword).toMatchObject({ requireEmailVerification: false, autoSignIn: true });
expect(options.emailAndPassword.resetPasswordTokenExpiresIn).toBe(3600);
expect(options.emailVerification).toMatchObject({
sendOnSignUp: false, autoSignInAfterVerification: true, expiresIn: 3600,
diff --git a/lib/auth/server.ts b/lib/auth/server.ts
index 0abf91d..88ed92a 100644
--- a/lib/auth/server.ts
+++ b/lib/auth/server.ts
@@ -53,7 +53,8 @@ function createAuth() {
secret: required("BETTER_AUTH_SECRET"),
emailAndPassword: {
enabled: true,
- requireEmailVerification: true,
+ requireEmailVerification: false,
+ autoSignIn: true,
minPasswordLength: 6,
maxPasswordLength: 128,
resetPasswordTokenExpiresIn: 3600,