Skip to content

console(auth): /verify-email POSTs the token, but better-auth serves verify-email as GET only — every valid token shows "Verification failed: 404" #11633

Description

@objectstack-fleet

QA-source: objectstack-ai/objectstack#21784 · identity-auth.email-verification-loop · acceptance[2]

A clause of identity-auth.email-verification-loop fails in the ObjectStack 17.7 pre-release checklist run objectstack-ai/objectstack#21784 (framework subject 316be321e, console pin 2e818d0b51ec). An independent verifier (VF1, RUNNER rule 7) confirmed it: low (the mailed link points at the API GET, so the page is reached only when used directly). It predates the 17.6.0 console pin 31971ff1e; no open duplicate was found. Owner: objectui.

Reproduction

  1. Boot with OS_AUTH_AUDIENCE_POSTURE=open and OS_AUTH_AUDIENCE_SELF_REGISTRATION_PERMISSION_SET=showcase_member_default.
  2. Sign up a fresh address; read the token from its sys_email.body_text (link /api/v1/auth/verify-email?token={jwt}&callbackURL=%2F).
  3. Open /_console/verify-email?token={token} in a fresh context. Expected: success state, account verified. Actual: "Verification failed: 404"; sign-in still EMAIL_NOT_VERIFIED. POST /api/v1/auth/verify-email {"token":…} → 404 (body and query forms).
  4. Control: GET /api/v1/auth/verify-email?token={token} → 302 and sign-in then returns emailVerified:true.

Mechanism

objectui apps/console/src/pages/auth/VerifyEmailPage.tsx:47-62 POSTs {token}; better-auth 1.7.3 email-verification.mjs:125 declares /verify-email method: "GET" only, and the framework route ledger lists only GET /api/v1/auth/verify-email. better-auth is 1.7.3 at 17.6.0 and HEAD. The clause's POST wording is a checklist issue too (noted in the run record's checklist-accuracy findings).

Done when

The page verifies via GET (or the server mounts a POST twin), and a garbage token still renders the error state.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:identityLogin and identity — sign-up, sessions, organization membership, SSObugSomething isn't workingdomain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatpriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions