mirror of
https://github.com/HeyPuter/puter.git
synced 2026-10-01 17:47:07 +00:00
Follows the previous commit. Dropping the email field entirely went one step too far: without an address the temporary password shown once in the panel is the only copy, and an admin who closes that panel has to issue a new one. The field is back, marked optional, and now it buys something concrete. `team_account_created` carried no credential -- it said the team "will send you a temporary password separately". It now carries the username and the temporary password, so an admin who supplies an address hands nothing over by side channel. `#notifyUser` takes extra template variables, and both credential-issuing paths pass the one they just minted: provisioning and re-issue. Re-issue passing the fresh credential rather than the stale one is the case worth checking, and there is a test that asserts the old password is absent from that mail. With no address nothing is sent, which was already true -- `#notifyUser` returns early without one -- and is now covered. The docs said the notice carries no credential in two places. Both corrected. Falsified: dropping the credential from the re-issue call fails "emails the fresh credential on re-issue, not the old one" and nothing else. 178 backend tests, 326 GUI/SDK tests, typecheck clean.