QA-source: objectstack-ai/objectstack#21784 · identity-auth.email-verification-loop · acceptance[2]
A clause of identity-auth.email-verification-loop fails in the ObjectStack 17.7 pre-release checklist run objectstack-ai/objectstack#21784 (framework subject 316be321e, console pin 2e818d0b51ec). An independent verifier (VF1, RUNNER rule 7) confirmed it: low (the mailed link points at the API GET, so the page is reached only when used directly). It predates the 17.6.0 console pin 31971ff1e; no open duplicate was found. Owner: objectui.
Reproduction
- Boot with
OS_AUTH_AUDIENCE_POSTURE=open and OS_AUTH_AUDIENCE_SELF_REGISTRATION_PERMISSION_SET=showcase_member_default.
- Sign up a fresh address; read the token from its
sys_email.body_text (link /api/v1/auth/verify-email?token={jwt}&callbackURL=%2F).
- Open
/_console/verify-email?token={token} in a fresh context. Expected: success state, account verified. Actual: "Verification failed: 404"; sign-in still EMAIL_NOT_VERIFIED. POST /api/v1/auth/verify-email {"token":…} → 404 (body and query forms).
- Control:
GET /api/v1/auth/verify-email?token={token} → 302 and sign-in then returns emailVerified:true.
Mechanism
objectui apps/console/src/pages/auth/VerifyEmailPage.tsx:47-62 POSTs {token}; better-auth 1.7.3 email-verification.mjs:125 declares /verify-email method: "GET" only, and the framework route ledger lists only GET /api/v1/auth/verify-email. better-auth is 1.7.3 at 17.6.0 and HEAD. The clause's POST wording is a checklist issue too (noted in the run record's checklist-accuracy findings).
Done when
The page verifies via GET (or the server mounts a POST twin), and a garbage token still renders the error state.
Generated by Claude Code
QA-source: objectstack-ai/objectstack#21784 · identity-auth.email-verification-loop · acceptance[2]
A clause of
identity-auth.email-verification-loopfails in the ObjectStack 17.7 pre-release checklist run objectstack-ai/objectstack#21784 (framework subject316be321e, console pin2e818d0b51ec). An independent verifier (VF1, RUNNER rule 7) confirmed it: low (the mailed link points at the API GET, so the page is reached only when used directly). It predates the 17.6.0 console pin31971ff1e; no open duplicate was found. Owner: objectui.Reproduction
OS_AUTH_AUDIENCE_POSTURE=openandOS_AUTH_AUDIENCE_SELF_REGISTRATION_PERMISSION_SET=showcase_member_default.sys_email.body_text(link/api/v1/auth/verify-email?token={jwt}&callbackURL=%2F)./_console/verify-email?token={token}in a fresh context. Expected: success state, account verified. Actual: "Verification failed: 404"; sign-in stillEMAIL_NOT_VERIFIED.POST /api/v1/auth/verify-email {"token":…}→ 404 (body and query forms).GET /api/v1/auth/verify-email?token={token}→ 302 and sign-in then returnsemailVerified:true.Mechanism
objectui
apps/console/src/pages/auth/VerifyEmailPage.tsx:47-62POSTs{token}; better-auth 1.7.3email-verification.mjs:125declares/verify-emailmethod: "GET"only, and the framework route ledger lists onlyGET /api/v1/auth/verify-email. better-auth is 1.7.3 at 17.6.0 and HEAD. The clause's POST wording is a checklist issue too (noted in the run record's checklist-accuracy findings).Done when
The page verifies via GET (or the server mounts a POST twin), and a garbage token still renders the error state.
Generated by Claude Code