Skip to content

Make account verification reactive across windows #297

Description

@th0rgall

Repro

Since the fixes mentioned here #98 (comment), the following scenario works:

  1. Create an account in tab A in window W
  2. Open a verification link via email in tab B in window W
  3. Both tab A & B will have been notified of a fully verified account.

However, these updates don't seem to propagate across windows:

  1. Create an account in tab A in window W (e.g. on your mobile phone)
  2. Open a verification link via email in tab B in window D (e.g. on your desktop)
  3. The account Tab A will be unverified until you reload the page.

There are also different scenarios possible for how Tab B looks when opened in a different context from tab A. See #298.

Solution

If verification state does not sync across windows, it will also not sync across two browsers which are simultaneously logged in.

First double-check that onIdTokenChanged is still not reacting on verification actions from other browers.

To implement this, we would need to manually add an emailVerified property to a users-private doc (mirroring the token verification state on the browser that verifies), which is listened to by unverified clients, upon which they can reload the auth token.

Priority

This is low priority (almost a non-issue), since being logged in in two different windows or browsers while having an unverified account is likely not common at all. And even if you are, if you try to take an action that requires verification, we will in most cases attempt a token refresh in the background which loads the latest state.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions