Replace Meshkee password when linking an existing account to a new site.

Cross-site register now updates the password to the signup value and documents passwordUpdated for storefronts.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Alireza Hassani
2026-08-21 12:07:17 +03:30
co-authored by Cursor
parent b0d4916138
commit e027cc96ea
7 changed files with 29 additions and 13 deletions
+1 -1
View File
@@ -253,7 +253,7 @@ All routes are prefixed with `/api/v1`.
| Method | Path | Description |
|--------|------|-------------|
| POST | `/auth/register` | Customer registration by domain |
| POST | `/auth/register` | Customer registration by domain. Cross-site link updates Meshkee password to the new signup password (`passwordUpdated`). |
| POST | `/auth/login` | Cell + password |
| POST | `/auth/login-otp` | Passwordless login with SMS OTP |
| POST | `/auth/reset-password` | Reset password with SMS OTP |
+1 -1
View File
@@ -23,7 +23,7 @@ You are building a **Meshkee business website (storefront)**. You must use the M
1. Resolve tenant first: `GET /tenants/<WEBSITE_DOMAIN>` → save `businessId` from `id`.
2. All public content uses `/tenants/<WEBSITE_DOMAIN>/...` (no auth).
3. Cart, orders, favorites use `/businesses/<businessId>/...` with `Authorization: Bearer <accessToken>`.
4. Customer register body must include `"domain": "<WEBSITE_DOMAIN>"`. If the cell already exists on another Meshkee site and the password differs, API returns `409` with `CELL_EXISTS_OTHER_SITE:...`. Retry register with `"acknowledgeExistingAccount": true` to link that account (password/profile stay unchanged), then complete SMS OTP.
4. Customer register body must include `"domain": "<WEBSITE_DOMAIN>"`. If the cell already exists on another Meshkee site and the password differs, API returns `409` with `CELL_EXISTS_OTHER_SITE:...`. Retry register with `"acknowledgeExistingAccount": true` to link that account (profile unchanged; **password is replaced** with the new signup password), then complete SMS OTP.
5. Cell numbers are E.164 (`+98912...`).
6. Do not call dashboard/CMS routes (`/businesses/.../products` write APIs, media upload, domain-admin, etc.).
7. **Partner SMS** (`POST /public/sms/send`) is for external partner backends with an issued `X-Api-Key` only — not for normal storefront UI. See https://api.meshkee.com/docs/website/SMS.md
+1 -1
View File
@@ -1557,7 +1557,7 @@
},
"acknowledgeExistingAccount": {
"type": "boolean",
"description": "If true, link an existing Meshkee account from another website without matching its password. Existing password and profile stay unchanged."
"description": "If true, link an existing Meshkee account from another website without matching its password. Profile stays unchanged; password is replaced with the new signup password. Response may include passwordUpdated: true."
}
}
}