From a24a06002081ad71a78ffeff9072725ba39cf121 Mon Sep 17 00:00:00 2001
From: Jake Vanderwerf <get@jakevanderwerf.ca>
Date: Tue, 17 Feb 2026 20:05:31 +0000
Subject: [PATCH] =minor changes, particularly around the JVB_CHILD_URL pattern

---
 inc/rest/routes/LoginRoutes.php |   43 +++++++++++++++----------------------------
 1 files changed, 15 insertions(+), 28 deletions(-)

diff --git a/inc/rest/routes/LoginRoutes.php b/inc/rest/routes/LoginRoutes.php
index ef66bb2..8ab30ce 100644
--- a/inc/rest/routes/LoginRoutes.php
+++ b/inc/rest/routes/LoginRoutes.php
@@ -39,7 +39,8 @@
 		Route::for('auth/status')
 			->get([$this, 'getAuthStatus'])
 			->auth('public')
-			->rateLimit(60, 60);
+			->rateLimit()
+			->register();
 
 		// Standard login
 		Route::for('auth/login')
@@ -51,7 +52,8 @@
 				'redirect_to' => 'string',
 			])
 			->auth('public')
-			->rateLimit(5, 300);
+			->rateLimit(5, 300)
+			->register();
 
 		// User registration
 		Route::for('auth/register')
@@ -64,7 +66,8 @@
 				'redirect_to' => 'string',
 			])
 			->auth('public')
-			->rateLimit(3, 3600);
+			->rateLimit(3, 3600)
+			->register();
 
 		// Request password reset
 		Route::for('auth/lostpassword')
@@ -73,7 +76,8 @@
 				'user_email' => 'email|required',
 			])
 			->auth('public')
-			->rateLimit(3, 3600);
+			->rateLimit(3, 3600)
+			->register();
 
 		// Reset password with token
 		Route::for('auth/resetpass')
@@ -85,7 +89,8 @@
 				'pass2' => 'string|required',
 			])
 			->auth('public')
-			->rateLimit(5, 300);
+			->rateLimit(5, 300)
+			->register();
 
 		// Magic link endpoint
 		if ($this->hasMagicLink) {
@@ -97,14 +102,16 @@
 					'redirect_to' => 'string',
 				])
 				->auth('public')
-				->rateLimit(5, 3600);
+				->rateLimit(5, 3600)
+				->register();
 		}
 
 		// Logout endpoint
 		Route::for('auth/logout')
 			->post([$this, 'handleLogout'])
 			->auth('logged_in')
-			->rateLimit(10, 60);
+			->rateLimit(10)
+			->register();
 	}
 
 	/**
@@ -333,7 +340,7 @@
 					'error' => $key->get_error_message(),
 				]);
 			} else {
-				$this->sendPasswordResetEmail($user, $key);
+				$success = JVB()->email()->sendPasswordResetEmail($user, $key);
 			}
 		}
 
@@ -703,26 +710,6 @@
 		}
 	}
 
-	/**
-	 * Send password reset email (fallback if magic links not available)
-	 */
-	protected function sendPasswordResetEmail(WP_User $user, string $key): bool
-	{
-		$reset_url = network_site_url(
-			"wp-login.php?action=rp&key=$key&login=" . rawurlencode($user->user_login),
-			'login'
-		);
-
-		$subject = 'Password Reset Request';
-		$message = sprintf(
-			"Hello %s,\n\nYou requested a password reset. Click the link below to reset your password:\n\n%s\n\nIf you didn't request this, please ignore this email.",
-			$user->display_name,
-			$reset_url
-		);
-
-		return wp_mail($user->user_email, $subject, $message);
-	}
-
 	protected function buildAuth(?int $user = null): array
 	{
 		if (is_user_logged_in()) {

--
Gitblit v1.10.0