You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
refactor(auth): the email-domain blocklist is configuration only (superdesigndev#373)
Removes BLOCKED_EMAIL_DOMAINS and BLOCKED_EMAIL_KEYWORDS from the code.
TREG_BLOCKED_EMAIL_DOMAINS is now the whole list, and an unset value blocks
nothing.
The substring rules were the reason to look. Measured against a public
throwaway-domain corpus they matched 0.17% of it, added nothing over the exact
domain entries, and refused a real company whose domain merely contained one of
the strings - with no way to unblock it short of a deploy, which is the opposite
of what a blocklist needs to be.
The shipped domain entries move to configuration for the same reason: a new
domain costs the other side minutes, so the list is only worth anything if it
can be edited in the same minutes.
|`TREG_META_CLIENT_ID` / `_SECRET`|*(empty)*| Meta app credentials for Facebook Pages, Meta Ads, and optional Instagram `page-tools`|
299
299
|`TREG_OAUTH_REVIEW_PENDING`|`instagram-login,page-messages`| Registry review keys awaiting production access. Remove `page-messages` after Page messaging approval; set empty after direct Instagram approval. |
300
300
|`TREG_RESEND_API_KEY` / `TREG_EMAIL_FROM`|*(empty)*| transactional email via Resend (OTP codes + invites); From must be a Resend-verified sender |
301
-
|`TREG_BLOCKED_EMAIL_DOMAINS`|*(empty)*| comma-separated email domains added to the built-in throwaway/farm blocklist, refused at every sign-up/sign-in door and at team creation (subdomains included, case-insensitive) |
301
+
|`TREG_BLOCKED_EMAIL_DOMAINS`|*(empty)*| comma-separated email domains refused at every sign-up/sign-in door and at team creation (subdomains included, case-insensitive). Empty blocks nothing — no list ships in the code|
302
302
|`TREG_ADMIN_TOKEN`|*(empty)*| cross-tenant **super-admin** bearer; authorizes every `/admin/*` endpoint. Empty disables the env path (only `is_superadmin` users reach `/admin`). Keep it long + secret. |
303
303
|`TREG_EMAIL_DEV_MODE`|`false`| when true, `/auth/email/start` returns the OTP in its response (no mail sender needed) — **dev/local only**, never in prod. |
0 commit comments