Identify accounts by a unique username, with the primary email as an alternative sign-in #1
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
What happens today
Accounts have no username at all. The custom user model removes the column and identifies people by email:
src/postulo/accounts/models.py—username = None,USERNAME_FIELD = "email",REQUIRED_FIELDS = [].src/postulo/config/settings/base.py—ACCOUNT_LOGIN_METHODS = {"email"},ACCOUNT_SIGNUP_FIELDS = ["email*", "password1*", "password2*"],ACCOUNT_USER_MODEL_USERNAME_FIELD = None.The email half of the requirement already holds:
emailisunique=Trueon the model andACCOUNT_UNIQUE_EMAIL = True, so a primary address is obligatory and unique across the instance.Everything downstream assumes email-only identity:
createsuperuserasks for email alone;User.display_namefalls back to the email local part; the invite adapter (accounts/adapter.py) binds invitations to an email; the export (core/export.py,accountsection) writesemail,first_name,last_name; the capture API's/api/v1/me(api/api.py) reports the owner by email;seed_demokeys on email.What changes
usernamecolumn onUser: obligatory, unique, validated (allowed characters, minimum length, reserved names), with a decision on case-sensitivity.ACCOUNT_USER_MODEL_USERNAME_FIELD = "username",ACCOUNT_LOGIN_METHODS = {"username", "email"}, addusername*toACCOUNT_SIGNUP_FIELDS. Sign-in form then accepts either.display_name(precedence to decide: full name › username › email),createsuperuser(REQUIRED_FIELDS), the export/import format (bumpFORMAT_VERSIONand carryusername),/api/v1/me,seed_demo, and the wiki pages Accounts and invitations and Getting started, which state that accounts are identified by email.Why this is a breaking change
createsuperuserprompts change.Open questions
admin,postulo, …), and whether it can be changed later.USERNAME_FIELDmove tousername, or stayemailwith username as an alternative login only? Moving it changesget_username()everywhere (tests assert it equals the email today) and whatcreatesuperuserasks first.Related: the full-name requirement and mandatory email verification are filed separately so each can land on its own.