feature: Web3 wallet authentication - #308
Merged
ayomideadeniran merged 2 commits intoApr 27, 2026
Merged
Conversation
|
@anonfedora Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
Contributor
|
pr under review, if i find any wrong implementation i will notify you. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Implements a complete Web3 wallet authentication system as a secure, non-custodial alternative to traditional email/password login. Users connect their MetaMask wallet, sign a server-issued cryptographic nonce, and receive JWT tokens upon successful signature verification — with no passwords stored or transmitted at any point.
The implementation covers the full stack: backend nonce generation and signature verification endpoints, frontend wallet connection service and UI component, database schema changes, rate limiting, and comprehensive documentation.
Backend
GET /api/auth/nonce— generates a unique 32-character cryptographic nonce, persists it with a 5-minute TTL via the newAuthNoncePrisma model, and returns it to the callerPOST /api/auth/verify— accepts a wallet address and signed message, cryptographically verifies the signature usingethers.js, maps the recovered address to a User record, and issues standard access/refresh JWT tokensFrontend
web3.service.ts— manages the full wallet connection lifecycle including provider detection, account access, message signing, and token storageWeb3Login.tsx— React component with MetaMask detection, connection state, and error handlingWeb3AuthExample.tsx— full-featured integration example page demonstrating the end-to-end authentication flowDocumentation
WEB3_AUTH_GUIDE.md— complete guide covering API reference, security considerations, integration instructions, and troubleshootingReference Issues
Closes #215
Type of Change
Checklist