Allow primary email for provisioend users

This commit is contained in:
binwiederhier
2026-06-22 12:59:50 -04:00
parent d8666b66ec
commit 4313b02fc6
8 changed files with 44 additions and 30 deletions
-8
View File
@@ -1669,10 +1669,6 @@ func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) {
if m.Kind != MagicLinkKindEmailVerify || time.Now().Unix() > m.Expires {
return nil, ErrMagicLinkNotFound
}
u, err := a.UserByID(m.UserID)
if err != nil {
return nil, err
}
err = db.ExecTx(a.db, func(tx *sql.Tx) error {
// Single use: delete the link, then add the (idempotent) verified address
if _, err := tx.Exec(a.queries.deleteMagicLinkByHash, tokenHash); err != nil {
@@ -1681,10 +1677,6 @@ func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) {
if _, err := tx.Exec(a.queries.insertEmailIgnore, m.UserID, m.Email); err != nil {
return err
}
// Must stay before the promotion block; covered by TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary
if u.Provisioned {
return nil // Provisioned users don't get a primary (recovery) email
}
// Promote to primary only if the user has none yet and the address is globally free.
// We check with SELECTs rather than catching a unique violation, because Postgres aborts
// the whole transaction on any constraint error (which would undo the verified-email add).
+4 -3
View File
@@ -3212,7 +3212,7 @@ func TestUser_MagicLink_ResetPassword_WrongKindRejected(t *testing.T) {
})
}
func TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary(t *testing.T) {
func TestUser_MagicLink_VerifyEmail_ProvisionedGetsPrimary(t *testing.T) {
forEachBackend(t, func(t *testing.T, newManager newManagerFunc) {
a := newTestManagerFromConfig(t, newManager, &Config{
DefaultAccess: PermissionDenyAll,
@@ -3224,7 +3224,8 @@ func TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary(t *testing.T) {
prov, err := a.User("prov")
require.Nil(t, err)
// A provisioned user can verify an email (for notifications), but it must NOT become primary
// A provisioned user's first verified email becomes their primary, just like a regular user
// (the primary is also the X-Email: yes target; password reset stays blocked separately).
_, err = a.VerifyEmail(addVerifyLink(t, a, prov.ID, "prov@example.com", time.Hour))
require.Nil(t, err)
@@ -3233,7 +3234,7 @@ func TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary(t *testing.T) {
require.Equal(t, []string{"prov@example.com"}, emails)
primary, err := a.PrimaryEmail(prov.ID)
require.Nil(t, err)
require.Equal(t, "", primary)
require.Equal(t, "prov@example.com", primary)
})
}