# Security Settings (Lumen Halo): prompt.md (v1.0.0)

- id: `lumen-security-settings` · version 1.0.0 · block · pro (Pro)
- category: App screens
- build: Base UI (one set of files; its dependencies follow the build)
- install (this build): `npx shadcn@latest add @beautiful-ui-pro/lumen-security-settings`
- npm dependencies: none
- registry dependencies: utils, @beautiful-ui/lumen-badge, @beautiful-ui/lumen-button, @beautiful-ui/lumen-field, @beautiful-ui-pro/lumen-input-otp, @beautiful-ui-pro/lumen-qr-code, @beautiful-ui/lumen-clipboard-button, @beautiful-ui-pro/lumen-password-field, @beautiful-ui-pro/lumen-safe-action, https://beautiful-ui.dev/r/lumen-foundation.json
- docs: https://beautiful-ui.dev/components/lumen-security-settings
- The install command carries everything this item needs (files, CSS, tokens, npm and registry dependencies). Prefer it to copying source by hand.

An account's security page: change password with the new one rated as you type; two-factor sign-in set up in place (scan or type the key, confirm a code, save recovery codes shown once); and the devices signed in, each signed out with a second press.

## Build it
- Stack: React 19 (`ref` is a plain prop), TypeScript, Tailwind CSS v4 utilities, a shadcn-initialised project with the `@/*` alias.
- Packages: none beyond React.
- Files: `components/ui/lumen/blocks/security-settings.tsx`.
- Registry dependencies, installed with it automatically: shadcn `utils` (cn), `lumen-badge`, `lumen-button`, `lumen-field`, `lumen-input-otp`, `lumen-qr-code`, `lumen-clipboard-button`, `lumen-password-field`, `lumen-safe-action`, `lumen-foundation`.
- Builds: one set of files for both, but its dependencies come in Base UI and Radix builds. Install the one that matches the project (see Install): a free item's bare URL installs the Base UI build of it and its dependencies.
- Exports to keep: `SecuritySettings`, and every exported type.
- CSS: the install merges this item's rules (the registry `css` field) into your global stylesheet, in `@layer components`, and adds the lumen foundation (tokens, keyframes, motion levels) once. Nothing to import by hand.
- Re-running `add` (or `--overwrite`) re-applies those rules: put overrides in your own CSS, never in the installed rules.
- Tokens: retheme with the `--lumen-*` custom properties (`--lumen-accent`, `--lumen-accent-foreground`, `--lumen-accent-text`, `--lumen-bad`, `--lumen-bad-text`, `--lumen-chart-accent`, `--lumen-chart-accent-foreground`, `--lumen-chart-accent-text`, `--lumen-focus`, `--lumen-good`, `--lumen-good-text`, `--lumen-hairline`, `--lumen-ink`, `--lumen-muted-ink`, `--lumen-series-1`, `--lumen-series-2`, `--lumen-series-3`, `--lumen-series-4`, `--lumen-series-5`, `--lumen-series-6`, `--lumen-warn`, `--lumen-warn-text`); this item's CSS also reads `--lumen-font-mono`, `--lumen-font-sans`, `--lumen-radius-k`. Never add Tailwind colour classes inside the component.

```tsx
import { SecuritySettings, type SecuritySession } from "@/components/ui/lumen/blocks/security-settings";
```

## Parts

| Part | data-slot | What it is for |
|---|---|---|
| `SecuritySettings` | `security-settings` | The password, two-factor and sessions sections. |

Style a part with `[data-slot="<slot>"]` selectors or its `className`; keep the attributes when editing.

## Sound
- Keep every `data-slot` and `data-sound` attribute: the sound layer reads them.
- Installing this item adds no audio. Nothing plays until the app mounts `GlassSoundProvider` once (install: `npx shadcn@latest add https://beautiful-ui.dev/r/glass-sound.json`, import from `@/components/beautiful-ui/glass-sound`); `GlassSoundToggle` is its mute control. Without a provider the audio engine never loads.

## Match the original
- Read `components/ui/lumen/blocks/security-settings.tsx` as the reference implementation before changing or recreating anything, and match it: sizes, colours per theme, motion timings, copy and behaviour.
- If you deviate (a prop you can't honour, a style you changed, a dependency you swapped), say so in your reply, part by part.
- Keep the accessibility contract, the keyboard map and the motion levels listed below.

## Use it when
- security settings, two-factor authentication, 2FA setup, TOTP, authenticator app, recovery codes, active sessions, sign out other devices, change password
- The security tab of account settings: password, two-factor and sessions in one place

### Not when
- Signing in or signing up: use Auth
- Workspace settings (name, time zone): use the Settings screen in SaaS Screens

## Mistakes
- Generate the secret, verify codes and store recovery codes on the server; the component never sees more than the setup response
- Update twoFactor and sessions yourself in the callbacks (the examples show how)
- Hash recovery codes before storing them, and show them only in the verify response

## Usage

```tsx
"use client";
import * as React from "react";
import { SecuritySettings, type SecuritySession } from "@/components/ui/lumen/blocks/security-settings";

async function post<T>(url: string, body?: unknown): Promise<T> {
  const res = await fetch(url, { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify(body ?? {}) });
  if (!res.ok) throw new Error((await res.json().catch(() => null))?.error ?? "Something went wrong. Try again.");
  return res.json();
}

export function SecurityPage({ initial }: { initial: { twoFactor: boolean; sessions: SecuritySession[] } }) {
  const [twoFactor, setTwoFactor] = React.useState(initial.twoFactor);
  const [sessions, setSessions] = React.useState(initial.sessions);
  return (
    <SecuritySettings
      onChangePassword={(input) => post("/api/account/password", input)}
      twoFactor={twoFactor}
      onStartTwoFactor={() => post("/api/account/2fa/start")}
      onVerifyTwoFactor={async (code) => {
        const r = await post<{ recoveryCodes: string[] }>("/api/account/2fa/verify", { code });
        setTwoFactor(true);
        return r;
      }}
      onDisableTwoFactor={async () => {
        await post("/api/account/2fa/disable");
        setTwoFactor(false);
      }}
      sessions={sessions}
      onSignOutSession={async (s) => {
        await post(`/api/account/sessions/${s.id}/revoke`);
        setSessions((all) => all.filter((x) => x.id !== s.id));
      }}
      onSignOutOthers={async () => {
        await post("/api/account/sessions/revoke-others");
        setSessions((all) => all.filter((x) => x.current));
      }}
    />
  );
}
```

## Props

| Prop | Type | Default | What it does |
|---|---|---|---|
| `onChangePassword` | `({ current, next }) => Promise<void>` |  | Change it; throw an Error with the message to show. Omit to hide the password section. |
| `twoFactor` | `boolean` |  | Two-factor is on now. |
| `onStartTwoFactor` | `() => Promise<{ secret, otpauthUrl }>` |  | Start setup on your server; the QR code shows otpauthUrl and the key is shown to type. |
| `onVerifyTwoFactor` | `(code) => Promise<{ recoveryCodes }>` |  | Check the 6-digit code; resolve with recovery codes (shown once), throw when it's wrong. |
| `onDisableTwoFactor` | `() => unknown` |  | Turn it off (asked for with a second press). |
| `sessions / onSignOutSession / onSignOutOthers` | `SecuritySession[] / (session) => unknown / () => unknown` |  | SecuritySession = { id, device, location?, lastActive, current? }. The current one can't be signed out here. |
| `labels` | `Partial<SecurityLabels>` |  | Every word, for i18n. |

Full docs: https://beautiful-ui.dev/components/lumen-security-settings

## Customising
- Colours: set the `--lumen-*` tokens on `:root`, or on a container with the `lumen-scope` class to retheme one area. Add the `lumen-inherit` class to follow your shadcn palette instead (`--chart-N`, `--destructive`).
- Dark mode follows the `.dark` class on an ancestor (the shadcn and next-themes convention).
- Update later by re-running the install with `--overwrite` (review the diff if you edited it). Changelog: https://beautiful-ui.dev/r/changelog.json

## Keyboard

| Keys | Action |
|---|---|
| Tab | Through each section's fields and buttons |
| Enter (password form) | Change password |
| Typing 6 digits | Verifies the code as soon as it's complete |
| Enter / Space (Sign out) | Arm it; focus moves to Cancel, Tab to the confirm button and press it |

## Performance

- Static sections; the QR code is computed once per secret

## Responsive

- Under 560px the password fields stack and the QR code sits above the setup steps

## Motion inventory

| Interaction | What moves |
|---|---|
| Two-factor setup | The setup tray unfolds in place; the QR code's cells resolve in |
| Sign out / turn off | Safe Action's confirm morph |

## Accessibility contract (preserve when editing)
- Three labelled sections; every field has a visible label and errors are announced (role alert) and tied to their field
- The setup key is readable text beside the QR code, so no one needs a camera; the code field is one-time-code autocomplete
- Two-factor state is a word (On / Off) as well as a dot; destructive actions (turn off, sign out) need a second press and name what they act on
- Focus moves to the code field when setup opens

## Install

```bash
npx shadcn@latest add @beautiful-ui-pro/lumen-security-settings
```

Pro item: needs the `@beautiful-ui-pro` registry in `components.json` and `BEAUTIFUL_UI_TOKEN` in `.env.local` (https://beautiful-ui.dev/account). Setup: https://beautiful-ui.dev/docs/pro. Your components.json `style` picks the build: radix-*, new-york and default get Radix, base-* gets Base UI.

The lumen foundation (the tokens listed above, keyframes and motion levels) installs once with the first component; its CSS is public at https://beautiful-ui.dev/r/lumen-foundation.json.
