UpdateUserCommand.Email (Modules.Identity.Contracts/v1/Users/UpdateUser/UpdateUserCommand.cs:13) is validated as an e-mail address (UpdateUserCommandValidator.cs:27-29), but UpdateUserCommandHandler never passes it to IUserService.UpdateAsync, so a client that sends a new e-mail gets a 200 and nothing changes.
E-mail changes need a confirmation flow (GenerateChangeEmailTokenAsync / ChangeEmailAsync), so this shouldn't be wired straight through. Proposal: remove Email from UpdateUserCommand and its validator (a silent no-op is the worst option), and track a proper "change e-mail with confirmation" endpoint separately if we want one.
Found while reviewing #1425.
UpdateUserCommand.Email(Modules.Identity.Contracts/v1/Users/UpdateUser/UpdateUserCommand.cs:13) is validated as an e-mail address (UpdateUserCommandValidator.cs:27-29), butUpdateUserCommandHandlernever passes it toIUserService.UpdateAsync, so a client that sends a new e-mail gets a 200 and nothing changes.E-mail changes need a confirmation flow (
GenerateChangeEmailTokenAsync/ChangeEmailAsync), so this shouldn't be wired straight through. Proposal: removeEmailfromUpdateUserCommandand its validator (a silent no-op is the worst option), and track a proper "change e-mail with confirmation" endpoint separately if we want one.Found while reviewing #1425.