fix(accounts): Only re-send verification to unverified accounts #1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
A user is able to click on the re-send verification button in /accounts/email/ which will re-send another verification email again to the already verified email address if it was previously verified. This will check to see if that email address has already been verified and prevent the re-send verification email from sending out again to those verified users.
I decided to use "A link to activate your account has been emailed to the address provided" as the error message as opposed to "This e-mail has already been verified" to stay within OWASP guidelines - see the email privacy leak issue (if we decide on using this OWASP error messaging throughout allauth).
But I suppose changing the error message to something else would be okay for this particular case (in other places though OWASP wording would be better).
If you want to allow users to create their own custom message, comment out messages.error and use:
https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html