Codeberg/Community
54
325
Fork
You've already forked Community
12

e-Mail/account activation reports invalid/expired link/code #1631

Open
opened 2024年08月13日 18:33:17 +02:00 by fbender · 8 comments

Comment

I've just signed up to Codeberg via Github auth in my macOS Safari private browsing window. The sign up flow ultimately had me input an email address and then asked to confirm via the link received via email within 3 hrs.

It took a few minutes (maybe 10 min?) for the mail to be received. Because I like it needlessly complicated, I found the mail on my phone (link preview is disabled) and sent the link to my Mac via AirDrop to open in Safari.

I was then greeted with an error message from Codeberg saying the link was invalid or expired (also after trying multiple different ways to open the link). Since this all happened within maybe 15-20 min max., the link should have been valid. I assume my phone did in fact not preview/prefetch the link before it was opened in my browser's window.

I've then tried to log in to my profile via Github, which was evidently successful. I don't see a way to confirm whether my email was successfully confirmed. Did I miss something?

If it was not confirmed: Is it possible that there's an (e.g. timing) issue with email link validation code?

If the email was confirmed without me ever seeing a success message (e.g. there was in fact a prefetch by my phone of some sort): Maybe it would be better to show a better error, or rather success message for more-or-less-recent validation codes that were registered as successful? E.g. "The confirmation was already successful, please continue to login." or similar.

Or maybe it's something weird involving the register/login-with-Github flow, or the fact that it's Safari or a private browsing session?

### Comment I've just signed up to Codeberg via Github auth in my macOS Safari private browsing window. The sign up flow ultimately had me input an email address and then asked to confirm via the link received via email within 3 hrs. It took a few minutes (maybe 10 min?) for the mail to be received. Because I like it needlessly complicated, I found the mail on my phone (link preview is disabled) and sent the link to my Mac via AirDrop to open in Safari. I was then greeted with an error message from Codeberg saying the link was invalid or expired (also after trying multiple different ways to open the link). Since this all happened within maybe 15-20 min max., the link should have been valid. I assume my phone did in fact not preview/prefetch the link before it was opened in my browser's window. I've then tried to log in to my profile via Github, which was evidently successful. I don't see a way to confirm whether my email was successfully confirmed. Did I miss something? If it was not confirmed: Is it possible that there's an (e.g. timing) issue with email link validation code? If the email was confirmed without me ever seeing a success message (e.g. there was in fact a prefetch by my phone of some sort): Maybe it would be better to show a better error, or rather success message for more-or-less-recent validation codes that were registered as successful? E.g. "The confirmation was already successful, please continue to login." or similar. Or maybe it's something weird involving the register/login-with-Github flow, or the fact that it's Safari or a private browsing session?
Owner
Copy link

It looks like all your email addresses are actually activated. To me, this sounds like a bug (maybe it generates the activation email when there is no need to do this).

You don't have to worry, but I'll leave this open for further investigation.

It looks like all your email addresses are actually activated. To me, this sounds like a bug (maybe it generates the activation email when there is no need to do this). You don't have to worry, but I'll leave this open for further investigation.

Facing something that sounds quite similar.

I get the activation email, get to a page with a Password prompt and a confirmation button. On clicking the button I'm hit with a 500 Internal Server Error.

As far as I can see, in my case the activation actually does fail.

Facing something that sounds quite similar. I get the activation email, get to a page with a Password prompt and a confirmation button. On clicking the button I'm hit with a 500 Internal Server Error. As far as I can see, in my case the activation actually does fail.
Owner
Copy link

We have observed this becoming an increasing pattern, indeed. My no-background-suspicion would be a deadlock or some other issue while actually writing to the email address. So the user account is marked as activated, and works afterwards. But the actual email is not marked as activated.

@ashimokawa Can you try to find the cause for this?

We have observed this becoming an increasing pattern, indeed. My no-background-suspicion would be a deadlock or some other issue while actually writing to the email address. So the user account is marked as activated, and works afterwards. But the actual email is not marked as activated. @ashimokawa Can you try to find the cause for this?

@fnetX wrote in #1631 (comment):

We have observed this becoming an increasing pattern, indeed. My no-background-suspicion would be a deadlock or some other issue while actually writing to the email address. So the user account is marked as activated, and works afterwards. But the actual email is not marked as activated.

@ashimokawa Can you try to find the cause for this?

I've opened a separate ticket for the issue here:

#1992

Sorry for the duplication.

@fnetX wrote in https://codeberg.org/Codeberg/Community/issues/1631#issuecomment-5537018: > We have observed this becoming an increasing pattern, indeed. My no-background-suspicion would be a deadlock or some other issue while actually writing to the email address. So the user account is marked as activated, and works afterwards. But the actual email is not marked as activated. > > @ashimokawa Can you try to find the cause for this? I've opened a separate ticket for the issue here: https://codeberg.org/Codeberg/Community/issues/1992 Sorry for the duplication.

@fnetX wrote in #1631 (comment):

We have observed this becoming an increasing pattern, indeed. My no-background-suspicion would be a deadlock or some other issue while actually writing to the email address. So the user account is marked as activated, and works afterwards. But the actual email is not marked as activated.

@ashimokawa Can you try to find the cause for this?

Yes, I will investigate.

This does indeed happen often it seems.

@fnetX wrote in https://codeberg.org/Codeberg/Community/issues/1631#issuecomment-5537018: > We have observed this becoming an increasing pattern, indeed. My no-background-suspicion would be a deadlock or some other issue while actually writing to the email address. So the user account is marked as activated, and works afterwards. But the actual email is not marked as activated. > > @ashimokawa Can you try to find the cause for this? Yes, I will investigate. This does indeed happen often it seems.
Owner
Copy link

FYi, another issue regarding email was traced back to a problem with capital letters in email addresses. Only lower-case emails seem to work right now. @fbender can you check if this also addresses your issue?

FYi, another issue regarding email was traced back to a problem with capital letters in email addresses. Only lower-case emails seem to work right now. @fbender can you check if this also addresses your issue?

This issue says they got an expired link code error.
I tried to reproduce this many times and failed.

@fbender
Then this issue also talks about github.com login.

Did you register another account using github and that worked?
also it should be possible to open the same link multiple times.
So prefetching should not be an issue...

This issue says they got an expired link code error. I tried to reproduce this many times and failed. @fbender Then this issue also talks about github.com login. Did you register another account using github and that worked? also it should be possible to open the same link multiple times. So prefetching should not be an issue...
Owner
Copy link

I understand the original issue that it is specific to registering via GitHub.

I understand the original issue that it is specific to registering via GitHub.
Sign in to join this conversation.
No Branch/Tag specified
main
No results found.
Labels
Clear labels
accessibility

Reduces accessibility and is thus a "bug" for certain user groups on Codeberg.
bug

Something is not working the way it should. Does not concern outages.
bug
infrastructure

Errors evidently caused by infrastructure malfunctions or outages
Codeberg

This issue involves Codeberg's downstream modifications and settings and/or Codeberg's structures.
contributions welcome

Please join the discussion and consider contributing a PR!
docs

No bug, but an improvement to the docs or UI description will help
duplicate

This issue or pull request already exists
enhancement

New feature
infrastructure

Involves changes to the server setups, use `bug/infrastructure` for infrastructure-related user errors.
legal

An issue directly involving legal compliance
licence / ToS

involving questions about the ToS, especially licencing compliance
please chill
we are volunteers

Please consider editing your posts and remember that there is a human on the other side. We get that you are frustrated, but it's harder for us to help you this way.
public relations

Things related to Codeberg's external communication
question

More information is needed
question
user support

This issue contains a clearly stated problem. However, it is not clear whether we have to fix anything on Codeberg's end, but we're helping them fix it and/or find the cause.
s/Forgejo

Related to Forgejo. Please also check Forgejo's issue tracker.
s/Forgejo/migration

Migration related issues in Forgejo
s/Pages

Issues related to the Codeberg Pages feature
s/Weblate

Issue is related to the Weblate instance at https://translate.codeberg.org
s/Woodpecker

Woodpecker CI related issue
security

involves improvements to the sites security
service

Add a new service to the Codeberg ecosystem (instead of implementing into Gitea)
upstream

An open issue or pull request to an upstream repository to fix this issue (partially or completely) exists (i.e. Gitea, Forgejo, etc.)
wontfix

Codeberg's current set of contributors are not planning to spend time on delegating this issue.
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
4 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Codeberg/Community#1631
Reference in a new issue
Codeberg/Community
No description provided.
Delete branch "%!s()"

Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?