trails/openspec/specs/journal-auth/spec.md
Ullrich Schäfer 7e253caf64
Archive account-settings change, sync specs
All 37 tasks complete. Synced delta specs to main:
- New: openspec/specs/account-settings/
- Updated: openspec/specs/journal-auth/

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-29 22:41:51 +02:00

1.4 KiB

MODIFIED Requirements

Requirement: Add passkey from new device

The Journal SHALL allow logged-in users to register additional passkeys from the account settings page or via the post-login prompt.

  • WHEN a user logs in via magic link on a device that supports WebAuthn
  • THEN the system prompts them to register a passkey for that device

Scenario: Add passkey from settings

  • WHEN a user clicks "Add passkey" in the security section of account settings
  • THEN the browser passkey creation prompt appears and the new passkey is stored

Scenario: Add passkey prompt on unsupported browser

  • WHEN a user logs in via magic link on a device that does not support WebAuthn
  • THEN the system shows the add-passkey prompt with a message that the browser does not support passkeys

ADDED Requirements

Requirement: Delete passkey

The Journal SHALL allow users to delete individual passkeys from account settings.

Scenario: Delete passkey

  • WHEN a user deletes a passkey from account settings
  • THEN the credential is removed from the database and can no longer be used for authentication

Scenario: Delete last passkey warning

  • WHEN a user attempts to delete their only remaining passkey
  • THEN a warning is shown explaining they will need to use magic links, and deletion proceeds after confirmation