Blog

All posts
John Damask · 2026-04-05
devloglaunchfrontend

One of the obvious things on my pre-launch checklist was "make users agree to the Terms of Service before creating their account." Easy feature, small code change, but I wanted to get one detail right: the ToS text shouldn't be duplicated anywhere.

The flow

When a visitor fills in email and password on the signup form and clicks Create Account, a modal intercepts the submit. The modal shows the full terms in a scrollable area, with a required checkbox at the bottom. If they check the box and click Accept, the Cognito signup call fires and they become a user. If they cancel, they go back to the form untouched.

The acceptance is captured server-side: the post-signup Lambda trigger now writes two fields into the user record -- a version string matching the effective date of the current terms, and an ISO-8601 timestamp of when the acceptance happened. DynamoDB is schema-less, so this was a pure code change with no migration or template edit. Since the checkbox is required before the Cognito signup call is even made, any user that reaches the post-signup trigger has accepted by construction.

The one-source-of-truth part

The interesting choice was where the terms text lives. The easy option is to paste it into the JavaScript that draws the modal. That works for one day, until you update the terms and forget to update the copy in the modal, and now two versions of the same document are live and disagreeing with each other.

Instead, the modal fetches the terms HTML at runtime from the public terms page, parses it, extracts the content div, and drops it into the modal body. One source of truth -- the terms page -- and the modal always reflects whatever is currently published. If the fetch ever fails, a fallback message appears but the checkbox stays functional so nobody gets stuck on an intermittent network blip.

Two files touched, a quick deploy to test, and one more pre-launch checkbox crossed off. Boring but important.