Skip to content

Email registration is not a sign-in; a password needs a confirmed email - #46

Merged
Ughuuu merged 2 commits into
mainfrom
email-registration-sdk-fix
Sep 27, 2026
Merged

Ughuuu merged 2 commits into
mainfrom
email-registration-sdk-fix

Conversation

@Ughuuu

@Ughuuu Ughuuu commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Email registration no longer signs in (register answers the account, not tokens), password login requires a confirmed email, and claiming an unconfirmed account by magic link or provider drops the password it was registered with.

POST /api/v1/register answered 201 with a full session while the
confirmation email was still queued, as device login does, and password
login worked on an address nobody had confirmed: anyone could register any
address and play as it.

The two flows are now separate. Device login still creates an account and
signs it in. Registering creates the account, queues the email and answers
201 with the account (Registration: user_id, username, display_name,
email_confirmed), never tokens. Password login, API and browser, answers
403 email_not_confirmed until the emailed link is opened, and only after
the right password. The first account is confirmed as it is created, so it
logs in at once.

An emailed login link still confirms, as it proves the inbox. On an
account registered with a password it used to raise; it now confirms and
removes that password, which whoever registered the address chose before
anyone proved they own it. The page the link opens says so, and the
confirmation email's link keeps the password.

SDKs: Godot's authenticate_register keeps no session, the C++
Auth::register_email takes a plain Callback and leaves the session alone,
and Balaur's client::register_email is a REST call rather than
gamend::register.
Signing in with a provider that asserts a verified email links it to the
account holding the address and confirms that account. When the account
had never been confirmed, it kept the password whoever registered the
address had chosen, so someone who registered a player's address first
could still sign in with it after the player claimed the account through
Google, Discord or another provider.

As an emailed login link already does, claiming an unconfirmed account now
removes its password and revokes every session, access and refresh token it
held (update_user_and_delete_all_tokens bumps token_version). The old
struct's cache keys are dropped and the revoked struct is re-warmed last.
Linking to a confirmed account is unchanged.
@Ughuuu
Ughuuu force-pushed the email-registration-sdk-fix branch from e9f81e1 to 1ab00a4 Compare September 27, 2026 08:38
@Ughuuu
Ughuuu merged commit 889eeef into main Sep 27, 2026
28 checks passed
@Ughuuu
Ughuuu deleted the email-registration-sdk-fix branch September 27, 2026 08:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant