The button element now takes an `icon`, so a page gets one by passing icon="name" rather than by hand-rolling its own button markup. Every button on the account and MFA screens carries one; a test walks each page and asserts no button is left bare. Change password: labels dropped (allauth already sets a placeholder on each field), the current password set apart from the new pair, help text kept on the new password, and Forgot Password promoted from a bare link to an accent button. MFA management: recovery-code actions are now ranked -- View is primary, Download and Generate are outline. Generate silently invalidates the codes you already hold, so it must not read as the obvious thing to click. Panel actions get breathing room from the body text (card-actions mt-4). Viewing recovery codes: Download and Generate sit side by side instead of stacking. TOTP activate: the code box loses its heading -- an otp field never takes a visible label, the boxes say what they are -- and the authenticator secret gets margin around it, since it is copied out by hand. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
40 lines
1.2 KiB
HTML
40 lines
1.2 KiB
HTML
{% extends "mfa/webauthn/base.html" %}
|
|
{% load allauth i18n static %}
|
|
|
|
{% block head_title %}
|
|
{% trans "Add Security Key" %}
|
|
{% endblock head_title %}
|
|
|
|
{% block content %}
|
|
{% element h1 %}
|
|
{% trans "Add Security Key" %}
|
|
{% endelement %}
|
|
|
|
{% url 'mfa_add_webauthn' as action_url %}
|
|
{% element form form=form method="post" action=action_url %}
|
|
{% slot body %}
|
|
{% csrf_token %}
|
|
{% element fields form=form %}
|
|
{% endelement %}
|
|
{% endslot %}
|
|
{% slot actions %}
|
|
{# type="button": the webauthn script takes over the click and posts the form itself. #}
|
|
{% element button id="mfa_webauthn_add" type="button" icon="usb" %}
|
|
{% trans "Add" %}
|
|
{% endelement %}
|
|
{% endslot %}
|
|
{% endelement %}
|
|
|
|
{% include "mfa/webauthn/snippets/scripts.html" %}
|
|
{{ js_data|json_script:"js_data" }}
|
|
<script data-allauth-onload="allauth.webauthn.forms.addForm" type="application/json">{
|
|
"ids": {
|
|
"add": "mfa_webauthn_add",
|
|
"passwordless": "{{ form.passwordless.auto_id }}",
|
|
"credential": "{{ form.credential.auto_id }}",
|
|
"data": "js_data"
|
|
}
|
|
}
|
|
</script>
|
|
{% endblock content %}
|