Skip to content

Require confirmed Bluesky email and explain video upload failures - #396

Merged
paulocastellano merged 4 commits into
mainfrom
fix/bluesky-email-confirmation
Oct 8, 2026
Merged

paulocastellano merged 4 commits into
mainfrom
fix/bluesky-email-confirmation

Conversation

@paulocastellano

@paulocastellano paulocastellano commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Bluesky accepts a valid session for an account whose email is unconfirmed, but its video service rejects uploads with HTTP 401 and jobStatus.error = unconfirmed_email. TryPost previously allowed that connection, repeated the upload three times, and saved only a generic media failure.

Require emailConfirmed === true before offering the account and recheck the authenticated session when finishing the connection. Missing confirmation, a mismatched identity, or an unsuccessful verification blocks saving. New connections and reconnects use the existing error screen with guidance translated into all 16 locales; failed reconnects preserve the existing account.

Parse session responses through the immutable App\Dto\BlueskySession DTO, shared by login, connection completion, token refresh, and app-password reauthentication. Validate identity and token types before using them, and preserve true/false/unknown email confirmation without coercion. Session lookups may omit tokens; login and refresh require both. A malformed refresh or mismatched identity preserves the stored credentials. Refreshing an existing session does not require email confirmation.

For already connected accounts, map unconfirmed_email to an actionable permission error: “Confirm your email in Bluesky settings, then try publishing again.” Stop further upload attempts, preserve the provider error and response in the post failure context, and avoid treating the valid session as expired or reporting an expected user-action rejection to Nightwatch. This also covers an email change after connection.

Only classify the video service's explicit email rejection through the session error mapper. Other video service responses keep their existing retry behavior, including service-token errors, malformed responses, and server failures.

Validation: 1,655 backend tests and 28 browser tests passed (8,974 assertions). The backend run covers the full social connection and publishing service suites, publication and refresh jobs, the publishing pipeline, the session DTO, and Bluesky error mapping. Browser coverage includes connection confirmation, switching accounts, and the channel posting-goal flow. Verified malformed and incomplete sessions, strict email confirmation, changed confirmation at finish, expired sessions, lost permissions, reconnect preservation, token renewal and reauthentication, provider failures, video retries, and actionable failure persistence. Pint and git diff --check passed.

@paulocastellano
paulocastellano merged commit 3117679 into main Oct 8, 2026
10 checks passed
@paulocastellano
paulocastellano deleted the fix/bluesky-email-confirmation branch October 8, 2026 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant