fix(users): an admin email edit must clear the stale verification

UpdateUser wrote a new address but kept email_verified, so patching a verified
account asserted a proof of an address nobody had proven — and the
pre-session login mails and resolves on exactly that flag, so a typo'd edit
could hand the account's sign-in codes to the wrong mailbox.

Changing the address now clears the flag in the same write; a no-op patch that
passes the same value keeps it. The fake mirrors the semantics, and the pgint
suite pins both halves (same value keeps proof, new value drops it).
This commit is contained in:
Lemon-miaow committed 2026-09-23 03:19:55 +08:00
1 parent b6ef27cd2d
commit d1ec40f738
3 files changed
+49 -1

No files matched your search

+6
View File
@@ -921,6 +921,12 @@ func (f *fakeRepo) UpdateUser(_ context.Context, userID string, patch UpdateUser
f.seededUsers[i].detail.Username = *patch.Username
}
if patch.Email != nil {
// Changing the address voids the proof of it, exactly like PGRepo:
// only VerifyEmailOTP may assert a verified address.
if *patch.Email != f.seededUsers[i].view.Email {
f.seededUsers[i].view.EmailVerified = false
f.seededUsers[i].detail.EmailVerified = false
}
f.seededUsers[i].view.Email = *patch.Email
f.seededUsers[i].detail.Email = *patch.Email
}
+9 -1
View File
@@ -1422,7 +1422,15 @@ func (p *PGRepo) UpdateUser(ctx context.Context, userID string, patch UpdateUser
}
if patch.Email != nil {
argn++
sets = append(sets, fmt.Sprintf("email = NULLIF($%d, '')", argn))
// Changing the address voids any proof of it: only VerifyEmailOTP may assert
// a verified address (mirrors SetUserEmail's rationale — a fresh, unproven
// value must not keep a stale verified flag that would let the pre-session
// email login resolve the account). A no-op edit that passes the same value
// keeps the flag; the second expression reads the OLD row, so comparing
// there is exact.
sets = append(sets,
fmt.Sprintf("email = NULLIF($%d, '')", argn),
fmt.Sprintf("email_verified = (email_verified AND email IS NOT DISTINCT FROM NULLIF($%d, ''))", argn))
args = append(args, *patch.Email)
}
if patch.Role != nil {