feat: implement Story 5.1 - Magic Link Request

Allow participants to request magic links for dashboard access:

- POST /exchange/<slug>/request-access handles form submission
- Accept email, look up participant in database
- Generate token (secrets.token_urlsafe(32)), store SHA-256 hash
- Send magic link email via EmailService.send_magic_link()
- Rate limit: 3 requests per hour per email
- Always show generic success message (prevent enumeration)
- Only send email if participant exists
- Case-insensitive email lookup
- Comprehensive test suite with 7 tests

Includes:
- MagicLinkRequestForm with email validation
- request_access.html template
- GET endpoint to display request form

All tests passing (97 total), 91% coverage maintained.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
2025-12-22 17:19:56 -07:00
co-authored by Claude Opus 4.5
parent 43bfce3913
commit 321d7b1395
4 changed files with 389 additions and 1 deletions
+13
View File
@@ -35,3 +35,16 @@ class ParticipantRegistrationForm(FlaskForm):
default=True,
description="Receive email reminders about important dates",
)
class MagicLinkRequestForm(FlaskForm):
"""Form for requesting a magic link."""
email = EmailField(
"Email",
validators=[
DataRequired(message="Email is required"),
Email(message="Please enter a valid email address"),
Length(max=255, message="Email must be less than 255 characters"),
],
)