auth-common:0.29.0, jwt:0.13.13, auth-client-sdk:0.20.1, auth-react-provider:0.16.38, auth-ui:0.18.0, openapi-operations:0.4.1, auth-resource-server-codegen-templates:0.0.153, auth-server-sdk:0.31.3, trpc-backend-init:0.9.69, auth-server:0.47.0, cypress-e2e-auth-tests-helper-commands:0.5.7, e2e-auth-tests:0.11.32 - require a verified email before handing users off to third-party apps - #239
Merged
Merged
Conversation
…rovider:0.16.38, auth-ui:0.18.0, openapi-operations:0.4.1, auth-resource-server-codegen-templates:0.0.153, auth-server-sdk:0.31.3, trpc-backend-init:0.9.69, auth-server:0.47.0, cypress-e2e-auth-tests-helper-commands:0.5.7, e2e-auth-tests:0.11.32 - require a verified email before handing users off to third-party apps Users must verify their email address before the auth server redirects them to an external (third-party) client application. The auth server's own /account flow stays open to unverified accounts so they can manage the account and re-send the verification link. - New server setting `require_email_verification_for_third_party_apps` (boolean, default on, editable on /admin/settings). - `isEmailVerificationRequiredForClientApp()` is consulted by every surface that mints an authorization code: POST /api/auth/login, /api/auth/register, /api/auth/mfa/verify, the session mint behind the consent screen (403 `error_id: email_verification_required`) and the already-signed-in branch of /auth/login (redirect). Gated login / register / MFA answers are a new `AuthenticateResult` kind, `email_verification_required` (session cookie set, no code). - New interstitial /auth/verify-email/required carrying the flow's parameters: shows the app and the address, offers a resend, polls whoami and resumes the flow through /auth/login?<params> once the address is verified. The login form, the MFA challenge page (form + passkey button) and the consent screen route gated flows to it. - `<EmailVerificationBanner />` nudges unverified users on every dashboard page. - OpenAPI: `EmailVerificationRequiredResult`, response docs updated. - E2E: `cy.verify_email_via_request()`, the resource-server PKCE helpers walk through the interstitial, third-party sign-in specs verify their users first, new `EmailVerificationRequiredForThirdPartyApps.cy.ts`. Co-Authored-By: Claude Fable 5.1 <[email protected]> Claude-Session: https://claude.ai/code/session_011LjMhRrZVZoysUAg7xpwd7
…-auth-tests:0.11.32 - keep the consent button disabled until the auth client is ready The example_resource_server E2E suite stalled on the server-rendered consent page that the verify-email interstitial resumes into: its "Authorize & Continue" handler returned early (with a "not ready" toast) when clicked before the SDK had hydrated and initialised from the session cookie, so a click landing in that window did nothing and the flow never reached the resource server. - AppAuthorizationConsentScreen: the button stays disabled until the auth client is ready (also fixes the same early-click dead end for users). - E2E helpers: wait for the enabled consent button; the login helper decides the consent step from the check-authorization response instead of sniffing the page text (deterministic for never-consented users). - New spec: the already-signed-in case establishes its session through the browser login page, like the existing cross-origin session test. Co-Authored-By: Claude Fable 5.1 <[email protected]> Claude-Session: https://claude.ai/code/session_011LjMhRrZVZoysUAg7xpwd7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Users must verify their email address before the auth server redirects
them to an external (third-party) client application. The auth server's
own /account flow stays open to unverified accounts so they can manage
the account and re-send the verification link.
require_email_verification_for_third_party_apps(boolean, default on, editable on /admin/settings).
isEmailVerificationRequiredForClientApp()is consulted by everysurface that mints an authorization code: POST /api/auth/login,
/api/auth/register, /api/auth/mfa/verify, the session mint behind the
consent screen (403
error_id: email_verification_required) and thealready-signed-in branch of /auth/login (redirect). Gated login /
register / MFA answers are a new
AuthenticateResultkind,email_verification_required(session cookie set, no code).parameters: shows the app and the address, offers a resend, polls
whoami and resumes the flow through /auth/login? once the
address is verified. The login form, the MFA challenge page (form +
passkey button) and the consent screen route gated flows to it.
<EmailVerificationBanner />nudges unverified users on everydashboard page.
EmailVerificationRequiredResult, response docs updated.cy.verify_email_via_request(), the resource-server PKCE helperswalk through the interstitial, third-party sign-in specs verify their
users first, new
EmailVerificationRequiredForThirdPartyApps.cy.ts.Co-Authored-By: Claude Fable 5.1 [email protected]
Claude-Session: https://claude.ai/code/session_011LjMhRrZVZoysUAg7xpwd7