fix(users): an admin email edit must clear the stale verification
UpdateUser wrote a new address but kept email_verified, so patching a verified account asserted a proof of an address nobody had proven — and the pre-session login mails and resolves on exactly that flag, so a typo'd edit could hand the account's sign-in codes to the wrong mailbox. Changing the address now clears the flag in the same write; a no-op patch that passes the same value keeps it. The fake mirrors the semantics, and the pgint suite pins both halves (same value keeps proof, new value drops it).
This commit is contained in:
3 files changed
+49
-1
No files matched your search
@@ -921,6 +921,12 @@ func (f *fakeRepo) UpdateUser(_ context.Context, userID string, patch UpdateUser
|
||||
f.seededUsers[i].detail.Username = *patch.Username
|
||||
}
|
||||
if patch.Email != nil {
|
||||
// Changing the address voids the proof of it, exactly like PGRepo:
|
||||
// only VerifyEmailOTP may assert a verified address.
|
||||
if *patch.Email != f.seededUsers[i].view.Email {
|
||||
f.seededUsers[i].view.EmailVerified = false
|
||||
f.seededUsers[i].detail.EmailVerified = false
|
||||
}
|
||||
f.seededUsers[i].view.Email = *patch.Email
|
||||
f.seededUsers[i].detail.Email = *patch.Email
|
||||
}
|
||||
|
||||
@@ -1422,7 +1422,15 @@ func (p *PGRepo) UpdateUser(ctx context.Context, userID string, patch UpdateUser
|
||||
}
|
||||
if patch.Email != nil {
|
||||
argn++
|
||||
sets = append(sets, fmt.Sprintf("email = NULLIF($%d, '')", argn))
|
||||
// Changing the address voids any proof of it: only VerifyEmailOTP may assert
|
||||
// a verified address (mirrors SetUserEmail's rationale — a fresh, unproven
|
||||
// value must not keep a stale verified flag that would let the pre-session
|
||||
// email login resolve the account). A no-op edit that passes the same value
|
||||
// keeps the flag; the second expression reads the OLD row, so comparing
|
||||
// there is exact.
|
||||
sets = append(sets,
|
||||
fmt.Sprintf("email = NULLIF($%d, '')", argn),
|
||||
fmt.Sprintf("email_verified = (email_verified AND email IS NOT DISTINCT FROM NULLIF($%d, ''))", argn))
|
||||
args = append(args, *patch.Email)
|
||||
}
|
||||
if patch.Role != nil {
|
||||
|
||||
Reference in new issue
Block a user