allowDisposableEmails? | boolean | When true, the built-in disposable-email check is skipped during signup. Defaults to false (built-in check enforced). Set this to true when you want to enforce your own domain-policy logic via onBeforeSignup — for example, a service that classifies domains as public/disposable/custom with its own data sources and cache. Skipping the built-in check without registering an onBeforeSignup hook means disposable emails will be allowed to sign up. | packages/modelence/src/app/authConfig.ts:384 |
errorComponent? | (props) => string | null | undefined | Customizes how OAuth authentication errors are rendered. By default, OAuth errors are returned as JSON; providing this returns a custom HTML response instead, which is useful when the OAuth flow runs in a browser context. Receives { error, statusCode } and returns an HTML string (or null/undefined to fall back to the default JSON response). Always escape interpolated values to prevent XSS. | packages/modelence/src/app/authConfig.ts:362 |
generateHandle? | (props) => Promise<string> | string | Custom handle generator. If provided, overrides the default behavior (which derives the handle from the email local-part). Receives { email, firstName?, lastName? } and returns the desired handle synchronously or as a Promise<string>. If the returned handle collides with an existing one, Modelence appends a numeric suffix automatically. | packages/modelence/src/app/authConfig.ts:312 |
login? | AuthOption | Deprecated Use AuthConfig.onAfterLogin and AuthConfig.onLoginError instead. | packages/modelence/src/app/authConfig.ts:315 |
magicLink? | object | Enables passwordless magic link authentication. Disabled by default. Requires an email provider and delivery settings under the email option (see EmailConfig.magicLink). Example startApp({ auth: { magicLink: { enabled: true, allowSignup: true }, }, }); | packages/modelence/src/app/authConfig.ts:334 |
magicLink.allowSignup? | boolean | Allows a magic link (or its one-time code) to create an account when the email has no existing one — combined sign-in/sign-up, like OAuth. Disabled by default: unknown emails get the same generic “link sent” response but no email, and no account is ever auto-created. | packages/modelence/src/app/authConfig.ts:342 |
magicLink.enabled? | boolean | - | packages/modelence/src/app/authConfig.ts:335 |
oauthAccountLinking? | "auto" | "manual" | Controls how OAuth providers handle existing accounts with matching email. - ‘manual’ (default): Returns an error when an OAuth login matches an existing email. - ‘auto’: Automatically links the OAuth provider to the existing account if the provider email is verified. | packages/modelence/src/app/authConfig.ts:351 |
onAfterEmailVerification? | (props) => void | Fires after a user’s email is successfully verified (via the verification link or implicitly via password reset). Receives { provider, user, session, connectionInfo }. | packages/modelence/src/app/authConfig.ts:284 |
onAfterLogin? | (props) => void | Fires after a successful login (email/password or OAuth) once the session has been linked to the user. Receives { provider, user, session, connectionInfo }. Use for analytics, audit logging, or post-login side effects. | packages/modelence/src/app/authConfig.ts:243 |
onAfterOAuthLink? | (props) => void | Fires after an OAuth provider is linked to an existing account (either automatically when oauthAccountLinking: 'auto' or via an explicit link flow). Receives { provider, user, session, connectionInfo }. | packages/modelence/src/app/authConfig.ts:297 |
onAfterSignup? | (props) => void | Fires after a successful signup once the user record is created and the session is linked. Receives { provider, user, session, connectionInfo }. Common uses: send welcome email, create default workspace, track activation. | packages/modelence/src/app/authConfig.ts:271 |
onBeforeSignup? | (props) => void | Promise<void> | Hook fired after validation and the built-in disposable-email check, but before the new user document is inserted. Throwing aborts the signup — the thrown error is re-thrown to the caller and onSignupError fires. Use this to plug in a custom domain-policy check (e.g. a tenant-specific email-domain verification service) without having to disable the built-in disposable-email check. Invoked for 'email' and 'magicLink' provider signups. OAuth signups are not gated because OAuth providers (Google, GitHub, etc.) do not issue disposable accounts. | packages/modelence/src/app/authConfig.ts:264 |
onEmailVerificationError? | (props) => void | Fires when email verification fails (invalid or expired token). Receives { provider, error, session, connectionInfo }. | packages/modelence/src/app/authConfig.ts:290 |
onLoginError? | (props) => void | Fires when a login attempt fails. Receives { provider, error, session, connectionInfo }. Use for failure analytics or alerting — does NOT change the response sent to the client. | packages/modelence/src/app/authConfig.ts:249 |
onOAuthLinkError? | (props) => void | Fires when OAuth account linking fails. Receives { provider, error, session, connectionInfo }. | packages/modelence/src/app/authConfig.ts:303 |
onSignupError? | (props) => void | Fires when a signup attempt fails (validation, duplicate email, etc.). Receives { provider, error, session, connectionInfo }. Use for failure analytics — does NOT change the response sent to the client. | packages/modelence/src/app/authConfig.ts:278 |
rateLimits? | AuthRateLimitsConfig | Overrides the built-in rate limits for authentication endpoints. Each rule you provide is merged into the defaults by (bucket, type, window): matching tuples replace the default limit, new tuples are added, and unspecified defaults are preserved. See AuthRateLimitsConfig for full semantics and examples. | packages/modelence/src/app/authConfig.ts:371 |
signup? | AuthOption | Deprecated Use AuthConfig.onAfterSignup and AuthConfig.onSignupError instead. | packages/modelence/src/app/authConfig.ts:317 |
validatePassword? | (props) => void | Promise<void> | Password policy hook. Runs on every path that sets a password — signup and password reset today, plus any future change-password flow — after the built-in length checks (MIN_PASSWORD_LENGTH..MAX_PASSWORD_LENGTH) and before the password is hashed. Throw to reject the password; the thrown message is surfaced to the client. Prefer this over AuthConfig.validateSignup for password rules. validateSignup only runs at signup, so a policy enforced there alone can be bypassed by signing up with a compliant password and immediately resetting to a weaker one. Receives { password, email, context }, where context is the flow that triggered the check ('signup' or 'reset'). May be async. Example startApp({ auth: { validatePassword: ({ password }) => { if (password.length < 12) { throw new Error('Password must be at least 12 characters'); } }, }, }); | packages/modelence/src/app/authConfig.ts:228 |
validateProfileUpdate? | (props) => void | Promise<void> | Pre-update validation hook. Runs before a user’s profile fields (firstName, lastName, avatarUrl, handle) are written. Throw to reject the update — the thrown message is surfaced to the client. May be async. | packages/modelence/src/app/authConfig.ts:236 |
validateSignup? | (props) => void | Promise<void> | Pre-signup validation hook. Runs before a new user is created during email/password signup, after format checks but before duplicate detection. Throw to reject the signup — the thrown message is surfaced to the client. Receives the raw signup payload (email, password, and optional firstName, lastName, avatarUrl, handle). May be async. | packages/modelence/src/app/authConfig.ts:198 |