Email Verification, Security & Unified Profile
Learn how Coderyx protects enterprise workspaces using mandatory email verification gates, step-up security for sensitive transactions, and a single cross-product profile synchronization architecture.
Account created with secure salted hashing. Platform remains locked until email token verified.
Internal products verify email verification status before granting access tickets.
Sensitive actions (cancel sub, change password, MFA) require password re-confirmation.
1. Mandatory Email Verification
To defend against malicious bot registration, credential stuffing, and unvetted footprint scanning, all users must verify their email address before they can perform any platform actions:
- Automatic Redirect: Immediately following registration, unverified users are directed to
/email/verify. - Protected Dashboard Routes: All dashboard routes—including services, orders, subscriptions, and SSO launch routes—enforce Laravel's
verifiedmiddleware. - Branded Email Dispatch: Verification emails are dispatched carrying the official Coderyx logo and cryptographic signed URLs valid for 24 hours.
- Resend Option: If you did not receive your email, simply click Resend verification link on the verification notice screen.
2. Step-Up Password Confirmation
In accordance with modern zero-trust enterprise security (NIST SP 800-63B), Coderyx requires step-up authentication for high-impact and irreversible operations. Even if an active browser session exists, you must re-enter your password to execute:
- Updating Account Password: Prevents unauthorized session hijacking takeovers.
- Reconfiguring Multi-Factor Authentication (MFA): Prevents unauthorized key generation.
- Revoking Other Browser Sessions: Guarantees that only the legitimate owner can purge active sessions.
- Cancelling Active Subscriptions: Ensures accidental or unauthorized subscription termination is prevented.
auth.password_timeout). After 3 hours, attempting a sensitive operation prompts a fresh confirmation modal.
3. Unified Profile Picture Synchronization
Coderyx enforces a single cross-product profile picture policy:
How 1 Avatar Runs Across All Products:
- User uploads photo in Central Dashboard (
/dashboard/profile). Supported: JPG, PNG, WEBP up to 2MB. - Central stores the image in secure public storage (
/storage/avatars/{hash}.webp). - Central synchronously updates the avatar column in LeadFlow ERP (
coderyx_erpgo.users) and Guard (coderyx.users). - SSO ticket payloads deliver the resolved
avatar_urlupon every product launch. - In LeadFlow, the avatar renders in Team Chat Spaces (current user dot, message bubbles, DM lists, member rosters).
- In ProtoStudio, the avatar renders in project header collaborator circles and live review comments.
4. Multi-Factor Authentication (MFA)
You can secure your account using Time-based One-Time Passwords (TOTP) compatible with Google Authenticator, Microsoft Authenticator, 1Password, or Yubico:
- Navigate to Dashboard → Profile → Security.
- Click Enable Multi-Factor Authentication.
- Confirm your password (step-up verification).
- Scan the QR code with your authenticator app and enter the 6-digit confirmation code.
- Save your 8 emergency backup codes in a secure location.
5. Active Sessions & Device Audit
View all active devices currently authenticated to your account under Security Settings:
- Inspect client IP address, device type (Desktop/Mobile), browser user-agent, and last activity timestamp.
- Click Log Out Other Browser Sessions to immediately invalidate session tokens on all other computers, smartphones, or locations.