Repro
Since the fixes mentioned here #98 (comment), the following scenario works:
- Create an account in tab A in window W
- Open a verification link via email in tab B in window W
- Both tab A & B will have been notified of a fully verified account.
However, these updates don't seem to propagate across windows:
- Create an account in tab A in window W (e.g. on your mobile phone)
- Open a verification link via email in tab B in window D (e.g. on your desktop)
- The account Tab A will be unverified until you reload the page.
There are also different scenarios possible for how Tab B looks when opened in a different context from tab A. See #298.
Solution
If verification state does not sync across windows, it will also not sync across two browsers which are simultaneously logged in.
First double-check that onIdTokenChanged is still not reacting on verification actions from other browers.
To implement this, we would need to manually add an emailVerified property to a users-private doc (mirroring the token verification state on the browser that verifies), which is listened to by unverified clients, upon which they can reload the auth token.
Priority
This is low priority (almost a non-issue), since being logged in in two different windows or browsers while having an unverified account is likely not common at all. And even if you are, if you try to take an action that requires verification, we will in most cases attempt a token refresh in the background which loads the latest state.
Repro
Since the fixes mentioned here #98 (comment), the following scenario works:
However, these updates don't seem to propagate across windows:
There are also different scenarios possible for how Tab B looks when opened in a different context from tab A. See #298.
Solution
If verification state does not sync across windows, it will also not sync across two browsers which are simultaneously logged in.
First double-check that
onIdTokenChangedis still not reacting on verification actions from other browers.To implement this, we would need to manually add an
emailVerifiedproperty to ausers-privatedoc (mirroring the token verification state on the browser that verifies), which is listened to by unverified clients, upon which they can reload the auth token.Priority
This is low priority (almost a non-issue), since being logged in in two different windows or browsers while having an unverified account is likely not common at all. And even if you are, if you try to take an action that requires verification, we will in most cases attempt a token refresh in the background which loads the latest state.