Files
minstrel/web/src/routes/forgot-password/+page.svelte
T
bvandeusenandClaude Opus 5.5 b46c080d19
release / govulncheck (push) Successful in 17s
release / web (push) Successful in 1m11s
release / go (push) Successful in 1m26s
release / integration (push) Successful in 4m18s
release / android (push) Successful in 4m44s
release / Build signed APK (releases and dev) (push) Successful in 4m53s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 26s
release / Verify release artifacts (tag releases only) (push) Skipped
fix(web): all accent text and icons use accent-fg (#5318)
The raw accent fails AA as text on every dark surface, not only on its
own tint: 3.04:1 on the page, 2.70 on iron, 2.21 on slate, against 4.5.
accent-fg (the house formula, 45% toward parchment) measures 5.62 at
worst across both modes. The operator chose the readable colour over the
signature teal for text, on 2026-10-08.

- 36 sites swap. They are 35 Tailwind uses: links, "Now playing", the
  ingest progress line, active shuffle/repeat, the liked heart, the app
  download icon and its hover. The last is the alphabet rail's pending
  spinner in CSS. Icons follow the text: as graphics they need only
  3:1, and the raw accent misses even that on iron.
- check-tint-contrast adds accent to TEXT_NEVER_RAW, so a new raw
  text-accent or color: var(--fs-accent) fails the web lane. Run against
  the files before the swap, it finds all 36. Borders, rings and fills
  keep the raw accent.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-08 00:17:19 -04:00

78 lines
2.7 KiB
Svelte

<script lang="ts">
import { pageTitle } from '$lib/branding';
import { forgotPassword } from '$lib/auth/store.svelte';
import { rateLimitMessage } from '$lib/api/client';
let email = $state('');
let submitted = $state(false);
let submitting = $state(false);
let throttled = $state<string | null>(null);
async function onSubmit(e: SubmitEvent) {
e.preventDefault();
submitting = true;
throttled = null;
try {
await forgotPassword(email);
submitted = true;
} catch (err) {
// A throttled request says so: the server applies the limit whether
// or not the email is registered, so it reveals nothing, and a
// "check your inbox" for a mail that was never sent would mislead.
// Every other failure is swallowed and shows the same success
// message, mirroring the server's no-enumeration posture.
throttled = rateLimitMessage(err);
submitted = throttled === null;
} finally {
submitting = false;
}
}
</script>
<svelte:head><title>{pageTitle('Forgot password')}</title></svelte:head>
<main class="flex min-h-screen items-center justify-center bg-background text-text-primary">
<div class="w-full max-w-sm rounded-lg border border-border bg-surface p-6 shadow">
<h1 class="mb-6 text-center text-2xl font-semibold">Forgot password</h1>
{#if !submitted}
<p class="mb-4 text-sm text-text-secondary">
Enter your email. If an account uses it, you'll receive a reset link shortly.
</p>
<form class="space-y-4" onsubmit={onSubmit}>
<label class="block">
<span class="mb-1 block text-sm text-text-secondary">Email</span>
<input
id="email"
type="email"
required
autocomplete="email"
bind:value={email}
class="w-full rounded border border-border bg-background px-3 py-2 outline-none focus:border-accent"
/>
</label>
<button
type="submit"
disabled={submitting}
aria-busy={submitting ? 'true' : undefined}
class="w-full rounded bg-accent px-3 py-2 font-medium text-background disabled:opacity-60"
>
{submitting ? 'Sending…' : 'Send reset link'}
</button>
{#if throttled}
<p class="text-sm text-danger" role="alert">{throttled}</p>
{/if}
</form>
{:else}
<p class="text-sm text-text-primary">
If your email is on file, you'll receive a reset link shortly.
Check your inbox (and spam folder).
</p>
{/if}
<p class="mt-4 text-center text-sm text-text-secondary">
Remembered? <a href="/login" class="text-accent-fg hover:underline">Log in</a>
</p>
</div>
</main>