Changes the password. The server checks currentPassword, breach-checks
newPassword, and on an account with an authenticator takes a code or
recoveryCode -- or throws DVMfaRequired when neither was given and no
factor was presented recently. This device keeps the rotated session;
every other device signed in as this person is signed out, and the
answer is how many.
Presents a code from the account's authenticator, or one recovery code,
for a sign-in that threw DVMfaRequired. The person is signed in once
the server accepts it.
Deletes the account. confirmed is the person's explicit confirmation,
and nothing is sent without it; the server also asks for the
password, and a code or recoveryCode when there is a second
factor, then hands the person to the project's Data Compliance erasure
where one is configured. The device signs out once the server confirms.
Asks for the account's address to become email. A code goes to that
address, and nothing changes until confirmEmailChange presents it --
an address that changed unverified is a takeover with a password reset
attached.
Signing in with an e-mail address and a password. Once signed in it goes
to from when that is a path in this application -- where the generated
account pages' gate was sending the person -- and to / otherwise.
The provider DV.Auth uses when the application configured none. The
generated runtime installs one signing in through the application's own
backend; configure replaces it.
Makes a generated call refused for a missing second factor present
SecondFactorPage over the current screen and send the call again once
a factor is presented -- DVStepUp.challenge, unless the application
installed its own. Installed by the generated runtime.