Skip to content

fix(profile): apply sign-up's email validator on profile-update + account-create - #878

Merged
cristim merged 3 commits into
feat/multicloud-web-frontendfrom
fix/868-profile-email-validation
Jun 1, 2026
Merged

cristim merged 3 commits into
feat/multicloud-web-frontendfrom
fix/868-profile-email-validation

Conversation

@cristim

@cristim cristim commented May 30, 2026 •

Copy link
Copy Markdown
Member

Summary

QA User Profile 4.1: User-profile email update + account-create paths accepted addresses without a TLD (e.g. name@hostonly), locking the user out after save. The sign-up + login paths rejected these correctly.

Fix

  • Extracted shared validateEmailFormat (internal/api/validation.go) using net/mail.ParseAddress plus a dot-in-host check to reject TLD-less addresses.
  • Applied on profile-update + account-create + sign-up paths (defense-in-depth, server-side).
  • Account creation preserves the per-field error contract ("invalid contact_email format") so the existing client-side error mapping keeps working.

Frontend client-side validation continues to rely on the existing HTML5 + JS check in the sign-up form; backend is the security boundary.

Files changed

  • internal/api/validation.go (shared validator)
  • internal/api/handler_auth.go (apply on sign-up + profile-update)
  • internal/api/handler_accounts.go (preserve contact_email error message)
  • internal/auth/service_user.go (cleanup unused import)

Test plan

  • 1852 backend tests pass across internal/api/... + internal/auth/....
  • Manual: log in as a user, edit profile, type name@g, attempt Save -> rejected with "invalid email format"; try name@example.com -> accepted.

Closes #868.

Summary by CodeRabbit

Release Notes

  • Bug Fixes
    • Enhanced email validation to enforce RFC 5322 compliance and reject single-label domains (e.g., user@localhost), improving data integrity.
    • Standardized error messages for invalid email formats across account and profile management features.
    • Optimized profile update validation to prioritize email format verification.

The profile-update + account-create paths accepted addresses without a
TLD (e.g. name@hostonly), which locked users out after save. Now share
the sign-up validator (net/mail + dot-in-host check) on client and
backend. Account creation preserves the per-field error message
contract ("invalid contact_email format").

Closes #868.
@cristim cristim added triaged Item has been triaged priority/p2 Backlog-worthy severity/medium Moderate harm urgency/this-sprint Within the current sprint impact/many Affects most users effort/xs Trivial / one-liner type/bug Defect labels May 30, 2026
@coderabbitai

coderabbitai Bot commented May 30, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@cristim, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 40 minutes and 26 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 77425615-a32b-4af1-86e5-b0e1db25f6e3

📥 Commits

Reviewing files that changed from the base of the PR and between 38fecd2 and aca6c85.

📒 Files selected for processing (3)
  • internal/api/handler_accounts_test.go
  • internal/api/handler_auth_test.go
  • internal/api/validation_test.go
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/868-profile-email-validation

Comment @coderabbitai help to get the list of available commands and usage tips.

@cristim

cristim commented May 30, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 30, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Extract decodeProfilePasswords() from updateProfile so the function's
cyclomatic complexity drops from 11 to 9 (limit: 10). Pure extraction -
no behaviour change, same validation order, same error messages.
@cristim

cristim commented Jun 1, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

… 2 handler sites)

Add TestValidateEmailFormat (15 table cases) to lock in the #868 constraint
that TLD-less addresses like "user@host" are rejected. Extend
handler_auth_test.go with TestHandler_updateProfile_RejectsInvalidEmail and
TestHandler_updateProfile_AcceptsValidEmail to guard the profile-update path.
Extend handler_accounts_test.go with TestCreateAccount_RejectsTLDlessContactEmail
and TestCreateAccount_AcceptsValidContactEmail to guard the account-create path.
+20 tests, 1355 -> 1375.
@cristim

cristim commented Jun 1, 2026

Copy link
Copy Markdown
Member Author

Added regression tests: 15 validator unit cases (TestValidateEmailFormat) + 4 handler tests on both profile-update and account-create paths. Stash-verified TestHandler_updateProfile_RejectsInvalidEmail fails against pre-fix code (without the validateEmailFormat call in updateProfile, the mock has no UpdateUserProfile expectation set up so the test fails on the require.Error assertion). 1355 -> 1375 tests. @coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

@cristim That's a solid test coverage addition — 15 unit cases for TestValidateEmailFormat plus 4 handler-level integration tests, with the stash-verified regression guard confirming the test genuinely catches the pre-fix behavior. Triggering a review now!

✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim
cristim merged commit d701f30 into feat/multicloud-web-frontend Jun 1, 2026
4 checks passed
@cristim
cristim deleted the fix/868-profile-email-validation branch June 1, 2026 16:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/xs Trivial / one-liner impact/many Affects most users priority/p2 Backlog-worthy severity/medium Moderate harm triaged Item has been triaged type/bug Defect urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant