import { useState } from 'react' import { supabase } from '../../data/supabaseClient' /** * Auth gate: Google SSO (per organized-ideas.md §2 — no username prompt * here, since Google doesn't let us collect one before the redirect; a * first-time Google sign-in lands with no username and App.tsx routes them * to CompleteProfileScreen to set one) or manual email/password signup * (username collected up front here instead, email pulled from the form). * Manual signup respects the hard email-verification gate from * supabase/config.toml — sign-in is blocked until confirmed. */ export default function LoginScreen() { const [mode, setMode] = useState<'sign-in' | 'sign-up'>('sign-in') const [email, setEmail] = useState('') const [password, setPassword] = useState('') const [username, setUsername] = useState('') const [loading, setLoading] = useState(false) const [error, setError] = useState(null) const [confirmSent, setConfirmSent] = useState(false) const handleGoogleSignIn = async () => { setError(null) setLoading(true) const { error } = await supabase.auth.signInWithOAuth({ provider: 'google', options: { redirectTo: window.location.origin }, }) // On success this redirects the whole page to Google, so we only ever // reach here if kicking off the redirect itself failed. if (error) { setError(error.message) setLoading(false) } } const handleSubmit = async (e: React.FormEvent) => { e.preventDefault() setError(null) setLoading(true) try { if (mode === 'sign-in') { const { error } = await supabase.auth.signInWithPassword({ email, password }) if (error) throw error } else { const { error } = await supabase.auth.signUp({ email, password, options: { data: { username: username.trim() } }, }) if (error) throw error setConfirmSent(true) } } catch (err) { setError(err instanceof Error ? err.message : 'Something went wrong.') } finally { setLoading(false) } } if (confirmSent) { return (

Check your email

We sent a confirmation link to {email}. You'll need to confirm before you can sign in.

{import.meta.env.DEV && (

Local dev: open Mailpit at{' '} 127.0.0.1:54324 {' '} to see it — no real email is sent.

)}
) } return (

Diagrav

{mode === 'sign-in' ? 'Sign in' : 'Create an account'}

or
{mode === 'sign-up' && ( )}
{error &&

{error}

}
) }