mailship/src
Agent 9fa1f73316
All checks were successful
CI / checks (pull_request) Successful in 36s
fix: distinguish already-confirmed tokens from invalid ones; prevent duplicate active subscriptions
Problem
-------
1. Re-clicking an already-confirmed confirmation link (e.g. /confirm?token=…)
   returned  from confirmSubscription because the SQL WHERE
   clause required . The caller then threw an
   ActionError('invalid or expired') which rendered the 'Email not confirmed'
   error page — misleading for someone who had already confirmed.

2. A second PUT /subscription/email with the same email+frequency could
   silently bypass the upsert path when getSubscriptionByPubkey found the
   active row but updateSubscription returned it unchanged (email and
   frequency matched). While the unique index prevented a true duplicate
   INSERT, the code path was fragile and the regression test was missing.

Changes
-------
database.ts:
- confirmSubscription now returns { sub, alreadyConfirmed } | undefined.
  First it tries the existing UPDATE (unconfirmed tokens only). If that
  returns no rows, it looks up the key directly: if the row exists and is
  already confirmed, returns { sub, alreadyConfirmed: true }. If the row
  doesn't exist or is unsubscribed, returns undefined (invalid/expired).
- Exported new ConfirmResult type for callers.

actions.ts:
- confirmSubscriptionAction destructures the new return type.
- Only registers the cron job on fresh confirmation (not re-confirms).
- Returns the ConfirmResult so the route can distinguish the two cases.

server.ts:
- /confirm route checks result.alreadyConfirmed and renders
  confirm-already.html instead of confirm-success.html.

pages/confirm-already.html:
- New page with title 'Email already confirmed' and an info message
  explaining the address was already confirmed.

Tests:
- test/confirm-already-confirmed.test.ts — NEW (3 tests): first confirm
  succeeds with alreadyConfirmed=false; second confirm returns
  alreadyConfirmed=true; nonexistent token returns undefined.
- test/duplicate-subscription.test.ts — NEW (4 tests): full cycle of
  register → confirm → re-register → assert one active row with
  unchanged key, verifying the upsert is idempotent.
- Adapted 3 existing test files to destructure the new ConfirmResult.
2026-09-17 16:57:30 -04:00
..
emails Rename Popular/HasPopular → Latest/HasLatest in digest ts/mjml/render-preview 2026-09-14 13:00:07 -04:00
pages fix: distinguish already-confirmed tokens from invalid ones; prevent duplicate active subscriptions 2026-09-17 16:57:30 -04:00
worker fix digest job race: delete sent events by ID, not timestamp 2026-09-14 13:07:34 -04:00
actions.ts fix: distinguish already-confirmed tokens from invalid ones; prevent duplicate active subscriptions 2026-09-17 16:57:30 -04:00
alert.ts fix: remove unused imports and variables flagged by eslint 2026-09-10 17:03:35 -04:00
database.ts fix: distinguish already-confirmed tokens from invalid ones; prevent duplicate active subscriptions 2026-09-17 16:57:30 -04:00
digest.ts Rename Popular/HasPopular → Latest/HasLatest in digest ts/mjml/render-preview 2026-09-14 13:00:07 -04:00
env.ts Normalize EVENT_VIEWER_URL trailing slash once in env.ts, remove 6 ad-hoc strips 2026-09-16 09:28:03 -04:00
index.ts Initial mailship fork from anchor 2026-08-18 12:21:22 -04:00
mailer.ts Normalize EVENT_VIEWER_URL trailing slash once in env.ts, remove 6 ad-hoc strips 2026-09-16 09:28:03 -04:00
repository.ts Initial mailship fork from anchor 2026-08-18 12:21:22 -04:00
run.ts Initial mailship fork from anchor 2026-08-18 12:21:22 -04:00
server.ts fix: distinguish already-confirmed tokens from invalid ones; prevent duplicate active subscriptions 2026-09-17 16:57:30 -04:00
templates.ts Initial mailship fork from anchor 2026-08-18 12:21:22 -04:00
types.d.ts Initial mailship fork from anchor 2026-08-18 12:21:22 -04:00
util.ts Initial mailship fork from anchor 2026-08-18 12:21:22 -04:00