This document details the authentication subsystem, session management, Google OAuth integration, and account suspension/blocking lifecycle across StudyMart.
StudyMart provides a client-enforced authentication system with zero external server dependencies, powered by /js/services/authService.js and /js/services/authStorage.js.
sequenceDiagram
autonumber
actor User as User / Student / Teacher
participant Modal as Auth Modal (#login / #register)
participant Auth as AuthService (js/services/authService.js)
participant Status as AccountStatusService
participant Storage as localStorage
User->>Modal: Submit Credentials
Modal->>Status: Check Account Status (isAccountBlocked)
alt Account is Blocked / Suspended
Status-->>Modal: Account Status = BLOCKED / SUSPENDED
Modal->>User: Display Suspended Account Modal + Support Contact
else Account is Active
Status-->>Modal: Account Status = ACTIVE
Modal->>Auth: Validate Credentials
Auth->>Storage: Set studyMart_current_user in localStorage
Auth->>User: Update window.appState & Refresh UI / Route
end
- Flow:
- User opens Auth Modal (
showLogin()). - Input validation verifies non-empty email and password.
- System checks predefined test account credentials or accounts registered in
localStorage.getItem("studymart_users"). - System verifies account status using
getAccountStatus(email). - On success, populates
window.appState.userDataandwindow.appState.userRole, saves current session tolocalStorage.getItem("studymart_current_user"), and closes modal.
- User opens Auth Modal (
- Integration: Uses Google Identity Services (
https://accounts.google.com/gsi/client). - Client ID:
785176204167-qhliiiu5uomft3rqhucvb8q5nq9c7ian.apps.googleusercontent.com(configured in.env.example). - Handler:
handleGoogleSignIn(response)decodes the JWT credential payload (google.accounts.id.initialize), extracts user name, email, and picture, automatically provisions a student/teacher session, and logs the user in.
- Flow:
- User toggles Register tab (
showRegister()). - Role selection step: User selects between Student Account (
student) or Teacher Account (teacher). - Form validation verifies full name, valid email, strong password, and password confirmation matching.
- User account is saved to
localStorage.getItem("studymart_users")viasaveUserToStorage(). - Automatic login is triggered upon registration completion.
- User toggles Register tab (
StudyMart implements account enforcement via accountStatusService.js:
| Account Status | Applies To | Effect on Login & Navigation | Support Modal |
|---|---|---|---|
ACTIVE |
All Roles | Normal full access permitted | None |
BLOCKED |
Student Accounts | Login denied; active session instantly terminated; access blocked | Displays Suspended Modal |
SUSPENDED |
Teacher Accounts | Login denied; active session instantly terminated; access blocked | Displays Suspended Modal |
- Platform Owner Action: Platform Owner clicks Block on student or Suspend on teacher in
#owner/studentsor#owner/teachers. - Central State Sync:
setAccountStatus(identifier, status)updates all storage keys:- Central map:
studymart_account_statuses_v1 - Enrolled students map:
lms_enrolled_students_v1 - Teacher overrides map:
lms_owner_teachers_v1 - Users catalog:
studymart_users
- Central map:
- Session Interception: If the targeted user is currently logged in (
studyMart_current_user), their session is immediately purged,window.appState.isLoggedInset tofalse, andshowSuspendedAccountModal()displayed on screen. - Support Contact Info: The modal provides copyable support details:
- Email:
eslam.adel2596@gmail.com - Phone:
01153054568
- Email:
| Storage Key | Content Type | Purpose |
|---|---|---|
studymart_current_user |
JSON Object | Active user session profile, role, and credentials |
studymart_users |
JSON Array | Directory of all user accounts registered locally |
studymart_account_statuses_v1 |
JSON Object | Master index of blocked/suspended account statuses |
lms_enrolled_students_v1 |
JSON Array | Student list overrides and individual account statuses |
lms_owner_teachers_v1 |
JSON Object | Teacher list overrides and individual account statuses |