Add post-signup email verification without changing manual activation - #154
Merged
Conversation
3 tasks
Copilot
AI
changed the title
[WIP] Add email validation after users sign up
Add post-signup email verification without changing manual activation
Jul 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This introduces a separate email-verification step after signup while preserving the existing manual admin activation flow. New users can now confirm ownership of their email address, but verification alone does not activate the account.
Verification state
Profile.email_verifiedto persist whether a signup email has been confirmed.Signup email flow
/validate-email/link to the signup emails for basic, educational, and researcher plans.Verification endpoint
validate-emailview and route.User.is_active; admin activation remains the only activation path.Token handling
ACCOUNT_ACTIVATION_DAYS.Focused coverage
Profile.email_verifiedExample of the new link construction: