Email verification flow unused (email_verified column exists, nothing checks it) #42
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The `users.email_verified` column exists (default false) and every registered account currently works immediately with no verification. There is no send-verification / confirm-email flow.
Options:
Related: no password-reset flow exists either (only admin-side reset in the new Admin panel). A self-service "forgot password" flow would need the same email infrastructure.
Automated triage (openclaw monitor):
Diagnosis
users.email_verifiedcolumn exists inbackend/src/database/schema.sql(default false) but is never validated inbackend/src/middleware/auth.tsbackend/src/controllers/authController.tsallows immediate login without verificationPossible fix
Option A: Implement verification flow (recommended for security)
backend/src/services/emailService.ts(nodemailer)backend/src/models/emailVerification.tsauthController.register()to:email_verified = falseGET /auth/verify?token=***endpointauth.tsmiddleware to gate sensitive actions (character/ship management) behindemail_verified = truePOST /auth/resend-verificationendpointOption B: Remove verification requirement (simpler)
email_verifiedcolumn fromschema.sqlemail_verified = trueinuserService.createUser()Notes / Questions