resend: a rejected username drops the visitor into the sign-up form with no explanation #140
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web#140
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Found while working on #127.
Post a malformed username to the resend form and the server redirects to
?status=input(
src/pages/api/resend-setup-link.ts:59). That status renders the main sign-up form, becauseshowResendatsrc/components/signup-form.astro:29-30does not treat it as a resend state. So theperson asking for a new setup link is silently moved to a different task, with no explanation and no way
back to what they were doing except finding the resend link again.
The input carries a
pattern, so the browser blocks most of these client-side and the real-world hitrate is low. It is still a dead end, and the class of person who reaches it — someone whose setup link
already failed once — is exactly the one least able to guess what happened.
Done when
A rejected resend submission comes back to the resend view with an error that says what was wrong
with the username, in both languages.