Repository navigation
fix(profile): apply sign-up's email validator on profile-update + account-create - #878
Conversation
The profile-update + account-create paths accepted addresses without a
TLD (e.g. name@hostonly), which locked users out after save. Now share
the sign-up validator (net/mail + dot-in-host check) on client and
backend. Account creation preserves the per-field error message
contract ("invalid contact_email format").
Closes #868.
|
Warning Review limit reached
More reviews will be available in 40 minutes and 26 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (3)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
Extract decodeProfilePasswords() from updateProfile so the function's cyclomatic complexity drops from 11 to 9 (limit: 10). Pure extraction - no behaviour change, same validation order, same error messages.
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
… 2 handler sites) Add TestValidateEmailFormat (15 table cases) to lock in the #868 constraint that TLD-less addresses like "user@host" are rejected. Extend handler_auth_test.go with TestHandler_updateProfile_RejectsInvalidEmail and TestHandler_updateProfile_AcceptsValidEmail to guard the profile-update path. Extend handler_accounts_test.go with TestCreateAccount_RejectsTLDlessContactEmail and TestCreateAccount_AcceptsValidContactEmail to guard the account-create path. +20 tests, 1355 -> 1375.
|
Added regression tests: 15 validator unit cases (TestValidateEmailFormat) + 4 handler tests on both profile-update and account-create paths. Stash-verified TestHandler_updateProfile_RejectsInvalidEmail fails against pre-fix code (without the validateEmailFormat call in updateProfile, the mock has no UpdateUserProfile expectation set up so the test fails on the require.Error assertion). 1355 -> 1375 tests. @coderabbitai review |
|
✅ Actions performedReview triggered.
|
Summary
QA User Profile 4.1: User-profile email update + account-create paths accepted addresses without a TLD (e.g.
name@hostonly), locking the user out after save. The sign-up + login paths rejected these correctly.Fix
validateEmailFormat(internal/api/validation.go) usingnet/mail.ParseAddressplus a dot-in-host check to reject TLD-less addresses."invalid contact_email format") so the existing client-side error mapping keeps working.Frontend client-side validation continues to rely on the existing HTML5 + JS check in the sign-up form; backend is the security boundary.
Files changed
internal/api/validation.go(shared validator)internal/api/handler_auth.go(apply on sign-up + profile-update)internal/api/handler_accounts.go(preservecontact_emailerror message)internal/auth/service_user.go(cleanup unused import)Test plan
internal/api/...+internal/auth/....name@g, attempt Save -> rejected with "invalid email format"; tryname@example.com-> accepted.Closes #868.
Summary by CodeRabbit
Release Notes
user@localhost), improving data integrity.