Skip to content

auth-common:0.29.0, jwt:0.13.13, auth-client-sdk:0.20.1, auth-react-provider:0.16.38, auth-ui:0.18.0, openapi-operations:0.4.1, auth-resource-server-codegen-templates:0.0.153, auth-server-sdk:0.31.3, trpc-backend-init:0.9.69, auth-server:0.47.0, cypress-e2e-auth-tests-helper-commands:0.5.7, e2e-auth-tests:0.11.32 - require a verified email before handing users off to third-party apps - #239

Merged
jalexw merged 2 commits into
mainfrom
claude/friendly-brahmagupta-uszz5a
Sep 27, 2026

Conversation

@jalexw

@jalexw jalexw commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Users must verify their email address before the auth server redirects
them to an external (third-party) client application. The auth server's
own /account flow stays open to unverified accounts so they can manage
the account and re-send the verification link.

  • New server setting require_email_verification_for_third_party_apps
    (boolean, default on, editable on /admin/settings).
  • isEmailVerificationRequiredForClientApp() is consulted by every
    surface that mints an authorization code: POST /api/auth/login,
    /api/auth/register, /api/auth/mfa/verify, the session mint behind the
    consent screen (403 error_id: email_verification_required) and the
    already-signed-in branch of /auth/login (redirect). Gated login /
    register / MFA answers are a new AuthenticateResult kind,
    email_verification_required (session cookie set, no code).
  • New interstitial /auth/verify-email/required carrying the flow's
    parameters: shows the app and the address, offers a resend, polls
    whoami and resumes the flow through /auth/login? once the
    address is verified. The login form, the MFA challenge page (form +
    passkey button) and the consent screen route gated flows to it.
  • <EmailVerificationBanner /> nudges unverified users on every
    dashboard page.
  • OpenAPI: EmailVerificationRequiredResult, response docs updated.
  • E2E: cy.verify_email_via_request(), the resource-server PKCE helpers
    walk through the interstitial, third-party sign-in specs verify their
    users first, new EmailVerificationRequiredForThirdPartyApps.cy.ts.

Co-Authored-By: Claude Fable 5.1 [email protected]
Claude-Session: https://claude.ai/code/session_011LjMhRrZVZoysUAg7xpwd7

…rovider:0.16.38, auth-ui:0.18.0, openapi-operations:0.4.1, auth-resource-server-codegen-templates:0.0.153, auth-server-sdk:0.31.3, trpc-backend-init:0.9.69, auth-server:0.47.0, cypress-e2e-auth-tests-helper-commands:0.5.7, e2e-auth-tests:0.11.32 - require a verified email before handing users off to third-party apps

Users must verify their email address before the auth server redirects
them to an external (third-party) client application. The auth server's
own /account flow stays open to unverified accounts so they can manage
the account and re-send the verification link.

- New server setting `require_email_verification_for_third_party_apps`
  (boolean, default on, editable on /admin/settings).
- `isEmailVerificationRequiredForClientApp()` is consulted by every
  surface that mints an authorization code: POST /api/auth/login,
  /api/auth/register, /api/auth/mfa/verify, the session mint behind the
  consent screen (403 `error_id: email_verification_required`) and the
  already-signed-in branch of /auth/login (redirect). Gated login /
  register / MFA answers are a new `AuthenticateResult` kind,
  `email_verification_required` (session cookie set, no code).
- New interstitial /auth/verify-email/required carrying the flow's
  parameters: shows the app and the address, offers a resend, polls
  whoami and resumes the flow through /auth/login?<params> once the
  address is verified. The login form, the MFA challenge page (form +
  passkey button) and the consent screen route gated flows to it.
- `<EmailVerificationBanner />` nudges unverified users on every
  dashboard page.
- OpenAPI: `EmailVerificationRequiredResult`, response docs updated.
- E2E: `cy.verify_email_via_request()`, the resource-server PKCE helpers
  walk through the interstitial, third-party sign-in specs verify their
  users first, new `EmailVerificationRequiredForThirdPartyApps.cy.ts`.

Co-Authored-By: Claude Fable 5.1 <[email protected]>
Claude-Session: https://claude.ai/code/session_011LjMhRrZVZoysUAg7xpwd7
…-auth-tests:0.11.32 - keep the consent button disabled until the auth client is ready

The example_resource_server E2E suite stalled on the server-rendered
consent page that the verify-email interstitial resumes into: its
"Authorize & Continue" handler returned early (with a "not ready" toast)
when clicked before the SDK had hydrated and initialised from the session
cookie, so a click landing in that window did nothing and the flow never
reached the resource server.

- AppAuthorizationConsentScreen: the button stays disabled until the auth
  client is ready (also fixes the same early-click dead end for users).
- E2E helpers: wait for the enabled consent button; the login helper
  decides the consent step from the check-authorization response instead
  of sniffing the page text (deterministic for never-consented users).
- New spec: the already-signed-in case establishes its session through
  the browser login page, like the existing cross-origin session test.

Co-Authored-By: Claude Fable 5.1 <[email protected]>
Claude-Session: https://claude.ai/code/session_011LjMhRrZVZoysUAg7xpwd7
@jalexw jalexw self-assigned this Sep 27, 2026
@jalexw
jalexw merged commit b581bdc into main Sep 27, 2026
55 checks passed
@jalexw
jalexw deleted the claude/friendly-brahmagupta-uszz5a branch September 27, 2026 19:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants