Email verification flow unused (email_verified column exists, nothing checks it) #42

Open
opened 2026-08-23 05:42:07 +00:00 by nasandre · 1 comment
Owner

The `users.email_verified` column exists (default false) and every registered account currently works immediately with no verification. There is no send-verification / confirm-email flow.

Options:

  1. If verification is wanted: generate tokens, email link, gate sensitive actions until verified
  2. If not wanted: drop the column usage from serializers/UI or set it true on registration to avoid confusion

Related: no password-reset flow exists either (only admin-side reset in the new Admin panel). A self-service "forgot password" flow would need the same email infrastructure.

The \`users.email_verified\` column exists (default false) and every registered account currently works immediately with no verification. There is no send-verification / confirm-email flow. Options: 1. If verification is wanted: generate tokens, email link, gate sensitive actions until verified 2. If not wanted: drop the column usage from serializers/UI or set it true on registration to avoid confusion Related: no password-reset flow exists either (only admin-side reset in the new Admin panel). A self-service \"forgot password\" flow would need the same email infrastructure.
Owner

Automated triage (openclaw monitor):

Diagnosis

  • The users.email_verified column exists in backend/src/database/schema.sql (default false) but is never validated in backend/src/middleware/auth.ts
  • backend/src/controllers/authController.ts allows immediate login without verification
  • No email service infrastructure exists to send verification links
  • No verification tokens are generated or validated
  • Related: No password-reset flow exists (only admin-side reset)

Possible fix

Option A: Implement verification flow (recommended for security)

  1. Add email service: backend/src/services/emailService.ts (nodemailer)
  2. Create verification tokens: backend/src/models/emailVerification.ts
  3. Modify authController.register() to:
    • Generate token
    • Send verification email
    • Set email_verified = false
  4. Add GET /auth/verify?token=*** endpoint
  5. Update auth.ts middleware to gate sensitive actions (character/ship management) behind email_verified = true
  6. Add POST /auth/resend-verification endpoint
  7. Implement password-reset flow with same token system

Option B: Remove verification requirement (simpler)

  1. Drop email_verified column from schema.sql
  2. Set email_verified = true in userService.createUser()
  3. Remove verification checks from serializers

Notes / Questions

  • Is email infrastructure (SMTP/SendGrid) available?
  • What are security requirements for sensitive actions?
  • Should password-reset flow be implemented simultaneously?
  • What's the user base size for migration impact?
  • Which approach does the team prefer?
Automated triage (openclaw monitor): ## Diagnosis - The `users.email_verified` column exists in `backend/src/database/schema.sql` (default false) but is **never validated** in `backend/src/middleware/auth.ts` - `backend/src/controllers/authController.ts` allows immediate login without verification - No email service infrastructure exists to send verification links - No verification tokens are generated or validated - Related: No password-reset flow exists (only admin-side reset) ## Possible fix **Option A: Implement verification flow (recommended for security)** 1. Add email service: `backend/src/services/emailService.ts` (nodemailer) 2. Create verification tokens: `backend/src/models/emailVerification.ts` 3. Modify `authController.register()` to: - Generate token - Send verification email - Set `email_verified = false` 4. Add `GET /auth/verify?token=***` endpoint 5. Update `auth.ts` middleware to gate sensitive actions (character/ship management) behind `email_verified = true` 6. Add `POST /auth/resend-verification` endpoint 7. Implement password-reset flow with same token system **Option B: Remove verification requirement (simpler)** 1. Drop `email_verified` column from `schema.sql` 2. Set `email_verified = true` in `userService.createUser()` 3. Remove verification checks from serializers ## Notes / Questions - Is email infrastructure (SMTP/SendGrid) available? - What are security requirements for sensitive actions? - Should password-reset flow be implemented simultaneously? - What's the user base size for migration impact? - Which approach does the team prefer?
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
nasandre/wh40-rogue-trader#42
No description provided.