Repository navigation
Require confirmed Bluesky email and explain video upload failures - #396
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bluesky accepts a valid session for an account whose email is unconfirmed, but its video service rejects uploads with HTTP 401 and
jobStatus.error = unconfirmed_email. TryPost previously allowed that connection, repeated the upload three times, and saved only a generic media failure.Require
emailConfirmed === truebefore offering the account and recheck the authenticated session when finishing the connection. Missing confirmation, a mismatched identity, or an unsuccessful verification blocks saving. New connections and reconnects use the existing error screen with guidance translated into all 16 locales; failed reconnects preserve the existing account.Parse session responses through the immutable
App\Dto\BlueskySessionDTO, shared by login, connection completion, token refresh, and app-password reauthentication. Validate identity and token types before using them, and preserve true/false/unknown email confirmation without coercion. Session lookups may omit tokens; login and refresh require both. A malformed refresh or mismatched identity preserves the stored credentials. Refreshing an existing session does not require email confirmation.For already connected accounts, map
unconfirmed_emailto an actionable permission error: “Confirm your email in Bluesky settings, then try publishing again.” Stop further upload attempts, preserve the provider error and response in the post failure context, and avoid treating the valid session as expired or reporting an expected user-action rejection to Nightwatch. This also covers an email change after connection.Only classify the video service's explicit email rejection through the session error mapper. Other video service responses keep their existing retry behavior, including service-token errors, malformed responses, and server failures.
Validation: 1,655 backend tests and 28 browser tests passed (8,974 assertions). The backend run covers the full social connection and publishing service suites, publication and refresh jobs, the publishing pipeline, the session DTO, and Bluesky error mapping. Browser coverage includes connection confirmation, switching accounts, and the channel posting-goal flow. Verified malformed and incomplete sessions, strict email confirmation, changed confirmation at finish, expired sessions, lost permissions, reconnect preservation, token renewal and reauthentication, provider failures, video retries, and actionable failure persistence. Pint and
git diff --checkpassed.