Skip to content

Preserve verified plus addresses in dashboard signing links - #22

Open
YS-OH-CORE wants to merge 1 commit into
psf:mainfrom
YS-OH-CORE:fix/verified-plus-email-links
Open

YS-OH-CORE wants to merge 1 commit into
psf:mainfrom
YS-OH-CORE:fix/verified-plus-email-links

Conversation

@YS-OH-CORE

@YS-OH-CORE YS-OH-CORE commented Sep 25, 2026 •

Copy link
Copy Markdown

Fixes #21.

A contributor whose verified GitHub email is name+label@example.com is shown as unverified because the dashboard compares its normalized group key (name@example.com) against the original verified addresses. Passing that stripped address to /sign/ would also fail the sign view's exact verified-email check.

This associates each pending group with an actual verified address from the session and uses that address in the displayed signing link. A verified untagged address is preferred when available, preserving the existing path; otherwise the first verified alias is used. The original address, including its plus tag, is URL-encoded and carried through signing.

The existing email-normalization policy and the sign view's verification checks are unchanged. This fixes the dashboard's choice of an already authorized address; it does not make an unverified address acceptable to /sign/.

Validation:

  • Added 7 Django integration tests. A public Linux verification run, using the original Docker/Compose environment with Python 3.13.15, PostgreSQL 18.6, and the complete pinned requirements, verifies original: 14 passed → original with only the submitted tests: 19 passed, exactly 2 expected failures → submitted fix: 21 passed.
  • The harness checks exact failure names and the missing-link assertion message, test counts, exit codes, and zero errors/skips. It tests this PR's exact 0da7e2e794f5714321f18212aafd86978fb00896 source separately from the verification branch. This contributor-fork run is separate from upstream CI approval.
  • Tests exercise dashboard links, following the link to the review page, and a synthetic signing POST through the real session/view/database path. Only outbound GitHub interactions are mocked. Unverified-address GET/POST rejection, grouped aliases, plain-address preference, and GitHub noreply behavior are covered.
  • Black, isort, flake8, and makemigrations --check pass in that Linux run; local git diff --check also passes.
  • Earlier local validation also passed all 21 tests on Windows / Python 3.12.14 / PostgreSQL 17.11, excluding the Linux-only debugging tools memray and pystack. The Linux run includes both packages, with no dependency exclusions. This PR changes no dependency or workflow files. The existing django-tasks deprecation warning is also present on untouched upstream.

AI assistance disclosure: This contribution was prepared for Youngseok Oh (@YS-OH-CORE) using OpenAI Codex for implementation, testing, and review.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug normalising plus emails: "name@example.com is not verified with GitHub"

1 participant