Describe the bug
If the "Users must verify their email address" setting under Security > Settings > User Registration is enabled, newly registered users will be created with the EmailConfirmed flag set to false, as expected. If a user allows the confirmation link in the initial email to expire, they have no way to request that a new confirmation email be sent aside from having an administrator resend the confirmation email from the admin panel. This is perhaps not strictly a bug but is certainly undesirable UX. An unverified user who attempts to sign in will see a notification stating "You must confirm your email", but they will have no way to do so.
Somewhat related to #18298
Orchard Core version
2.2.1
To Reproduce
- As an admin user, enable the
OrchardCore.Users.Registration feature.
- Under Security > Settings > User Registration, check the "Users must verify their email address" setting.
- In an incognito window, browse to the site and register as a new user.
- At this stage, assume the user doesn't receive the confirmation email or allows it to expire
- Try to sign in.
- See notification indicating "You must confirm your email."
- There is no longer any way to confirm the email address aside from contacting an admin user or customer support to send a new email from the admin panel.
This would also affect customers created manually in the admin panel, via a recipe, etc. that do not have the EmailConfirmed property set to true on their User.
Expected behavior
It seems like a potential improvement would be to modify AccountController.AddConfirmEmailErrorAsync in OrchardCore.Users to send a confirmation email. By the time this method is invoked, the user's credentials have already been validated, so it would make sense to re-send the confirmation email and perhaps change the model state error in this method to "You must confirm your email. Please check your email for a link to verify your account." or something along those lines so that the user has a way of resolving the issue without needing to go through support.
Additional comments
This issue exists in base OrchardCore but is exacerbated by some custom user creation flows in my solution where we create users based on identity records in an external system and set the EmailConfirmed property to false when doing so.
Describe the bug
If the "Users must verify their email address" setting under Security > Settings > User Registration is enabled, newly registered users will be created with the
EmailConfirmedflag set tofalse, as expected. If a user allows the confirmation link in the initial email to expire, they have no way to request that a new confirmation email be sent aside from having an administrator resend the confirmation email from the admin panel. This is perhaps not strictly a bug but is certainly undesirable UX. An unverified user who attempts to sign in will see a notification stating "You must confirm your email", but they will have no way to do so.Somewhat related to #18298
Orchard Core version
2.2.1
To Reproduce
OrchardCore.Users.Registrationfeature.This would also affect customers created manually in the admin panel, via a recipe, etc. that do not have the
EmailConfirmedproperty set to true on theirUser.Expected behavior
It seems like a potential improvement would be to modify
AccountController.AddConfirmEmailErrorAsyncinOrchardCore.Usersto send a confirmation email. By the time this method is invoked, the user's credentials have already been validated, so it would make sense to re-send the confirmation email and perhaps change the model state error in this method to "You must confirm your email. Please check your email for a link to verify your account." or something along those lines so that the user has a way of resolving the issue without needing to go through support.Additional comments
This issue exists in base OrchardCore but is exacerbated by some custom user creation flows in my solution where we create users based on identity records in an external system and set the
EmailConfirmedproperty tofalsewhen doing so.