All checks were successful
CI / checks (pull_request) Successful in 36s
Problem
-------
1. Re-clicking an already-confirmed confirmation link (e.g. /confirm?token=…)
returned from confirmSubscription because the SQL WHERE
clause required . The caller then threw an
ActionError('invalid or expired') which rendered the 'Email not confirmed'
error page — misleading for someone who had already confirmed.
2. A second PUT /subscription/email with the same email+frequency could
silently bypass the upsert path when getSubscriptionByPubkey found the
active row but updateSubscription returned it unchanged (email and
frequency matched). While the unique index prevented a true duplicate
INSERT, the code path was fragile and the regression test was missing.
Changes
-------
database.ts:
- confirmSubscription now returns { sub, alreadyConfirmed } | undefined.
First it tries the existing UPDATE (unconfirmed tokens only). If that
returns no rows, it looks up the key directly: if the row exists and is
already confirmed, returns { sub, alreadyConfirmed: true }. If the row
doesn't exist or is unsubscribed, returns undefined (invalid/expired).
- Exported new ConfirmResult type for callers.
actions.ts:
- confirmSubscriptionAction destructures the new return type.
- Only registers the cron job on fresh confirmation (not re-confirms).
- Returns the ConfirmResult so the route can distinguish the two cases.
server.ts:
- /confirm route checks result.alreadyConfirmed and renders
confirm-already.html instead of confirm-success.html.
pages/confirm-already.html:
- New page with title 'Email already confirmed' and an info message
explaining the address was already confirmed.
Tests:
- test/confirm-already-confirmed.test.ts — NEW (3 tests): first confirm
succeeds with alreadyConfirmed=false; second confirm returns
alreadyConfirmed=true; nonexistent token returns undefined.
- test/duplicate-subscription.test.ts — NEW (4 tests): full cycle of
register → confirm → re-register → assert one active row with
unchanged key, verifying the upsert is idempotent.
- Adapted 3 existing test files to destructure the new ConfirmResult.
62 lines
No EOL
1.8 KiB
HTML
62 lines
No EOL
1.8 KiB
HTML
<!DOCTYPE html>
|
|
<html>
|
|
<head>
|
|
<meta charset="utf-8" />
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
|
<title>Email Already Confirmed</title>
|
|
<style>
|
|
* { box-sizing: border-box; }
|
|
body {
|
|
font-family: 'Inter', system-ui, -apple-system, sans-serif;
|
|
display: flex;
|
|
align-items: center;
|
|
justify-content: center;
|
|
min-height: 100vh;
|
|
margin: 0;
|
|
background: #f0f2f5;
|
|
color: #1e293b;
|
|
}
|
|
.container {
|
|
width: 100%;
|
|
max-width: 480px;
|
|
margin: 16px;
|
|
text-align: center;
|
|
padding: 40px 32px;
|
|
background: #ffffff;
|
|
border-radius: 12px;
|
|
border: 1px solid #e2e8f0;
|
|
}
|
|
.logo { height: 40px; width: auto; margin: 0 auto 16px; display: block; }
|
|
.brand {
|
|
font-size: 24px;
|
|
font-weight: 700;
|
|
margin: 0 0 28px;
|
|
color: {{brandAccent}};
|
|
}
|
|
.title {
|
|
font-size: 20px;
|
|
font-weight: 700;
|
|
margin: 0 0 12px;
|
|
color: #1e293b;
|
|
}
|
|
.message {
|
|
font-size: 15px;
|
|
line-height: 1.6;
|
|
color: #64748b;
|
|
margin: 0;
|
|
}
|
|
.message a { color: {{brandAccent}}; text-decoration: none; font-weight: 600; }
|
|
</style>
|
|
</head>
|
|
<body>
|
|
<div class="container">
|
|
{{#brandLogo}}<img class="logo" src="{{brandLogo}}" alt="{{brandName}}" />{{/brandLogo}}
|
|
<div class="brand">{{brandName}}</div>
|
|
<h1 class="title">Email already confirmed</h1>
|
|
<p class="message">
|
|
This email address has already been confirmed. You're all set — no further action needed.
|
|
Visit <a href="{{settingsUrl}}">{{brandName}}</a> to manage your notification settings.
|
|
</p>
|
|
</div>
|
|
</body>
|
|
</html> |