Test hosted sign-in and recovery
Use this checklist to test hosted sign-in, sign-up, password reset, logout, and invitation acceptance for the intended site.
- Open Sign In with a non-production account. A valid account reaches the configured destination; an invalid credential remains on the hosted flow so the user can correct it.
- Test Sign Up only when
security.signup-enabledis enabled. A successful registration follows the hosted outcome; when disabled, use an invitation instead of retrying sign-up. - Select Forgot Password, submit the eligible account, then complete the reset and use Back to Sign In or Continue to Sign In. For an expired or invalid reset path, restart from Forgot Password.
- Select Logout and verify the session ends before testing another account.
Two-factor authentication and email verification aren't available yet; the Enable 2FA security setting currently has no effect. For a hosted automatic redirect, use OpenID Connect SSO.
Open the hosted flow from your app#
Use the browser client from Get credentials to test the same flow from your app's buttons.
- JavaScript SDK
- Refine
taruvi is the browser client configured for the site. Bind these functions to
your app's sign-in, sign-up, and logout buttons. The callback stays on your app.
import {Auth} from '@taruvi/sdk';
const auth = new Auth(taruvi);
export function signIn() {
auth.login(window.location.origin);
}
export function signUp() {
auth.signup(window.location.origin);
}
export async function signOut() {
await auth.logout(window.location.origin);
}
Register authProvider(taruvi) using the Refine setup.
Use each mutation from its corresponding event handler. Offer sign-up when
it is enabled for the site.
import {useLogin, useLogout, useRegister} from '@refinedev/core';
import type {LoginParams, LogoutParams, RegisterParams} from '@taruvi/refine-providers';
const {mutate: login} = useLogin<LoginParams>();
const {mutate: register} = useRegister<RegisterParams>();
const {mutate: logout} = useLogout<LogoutParams>();
// Call from an event handler.
login({callbackUrl: window.location.origin});
// Call from an event handler.
register({callbackUrl: window.location.origin});
// Call from an event handler.
logout({callbackUrl: window.location.origin});
Continue the sign-in, recovery, and logout checks above on the hosted pages. Complete password reset and invitation acceptance on the corresponding hosted pages.
Accept an invitation#
Invitation links expire 7 days after they are sent. Opening a link also verifies that its token exists and that the invitation has not already been used.
- Select Accept Invitation from a valid invitation link and verify the organization and invited identifier shown by the hosted page.
- Review the prefilled name. Existing account details can be locked; a new invitee completes first name, last name, password, and password confirmation.
- Submit the invitation. After acceptance, the Console attempts sign-in. When the response includes an organization slug, it opens that organization; otherwise it returns to the organizations list.
- If automatic sign-in fails, use Try Login Again. If that retry cannot be completed, select Go to Login Page.
Recover an invitation link#
- Missing or invalid token — The hosted page shows an invalid-link error and can't load the invitation details. Select Go to Login, then ask the organization administrator to verify the Pending invitation. If the token is invalid, delete that invitation and send a new invitation.
- Expired — The link is rejected after the configured expiry period. Ask the administrator to delete the expired invitation and send a new invitation; resending the same expired record doesn't create a new expiry window.
- Already used or accepted — The link is rejected because invitation acceptance is complete. Select Go to Login and ask the administrator to verify the Accepted member, group, and site access. Don't send a duplicate invitation.
- Pending, but the email wasn't received — The invitation stays usable until it expires. Ask the administrator to use Resend invitation from Invitations, then retry the newest delivered link.
There is no supported decline action in the hosted page or invitation endpoint. An invitee who does not want to accept should ask the organization administrator to Delete the pending invitation.
For unresolved hosted-flow failures, see troubleshooting.