From 05d373081a14b3438826a1192c731a24dda04bcb Mon Sep 17 00:00:00 2001 From: DarkSky <25152247+darkskygit@users.noreply.github.com> Date: Thu, 9 Oct 2025 17:46:05 +0800 Subject: [PATCH] fix(server): update email verified at oauth (#13714) ## Summary by CodeRabbit * **New Features** * Automatic email verification when signing in or reconnecting with a linked OAuth provider: if the provider confirms the same email and your account was unverified, your email will be marked as verified automatically. --- packages/backend/server/src/plugins/oauth/controller.ts | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/packages/backend/server/src/plugins/oauth/controller.ts b/packages/backend/server/src/plugins/oauth/controller.ts index eb7e909e4..550378771 100644 --- a/packages/backend/server/src/plugins/oauth/controller.ts +++ b/packages/backend/server/src/plugins/oauth/controller.ts @@ -221,6 +221,15 @@ export class OAuthController { if (connectedAccount) { // already connected await this.updateConnectedAccount(connectedAccount, tokens); + + if ( + !connectedAccount.user.emailVerifiedAt && + // external email may change, check if it matches exists email + externalAccount.email.toLowerCase() === + connectedAccount.user.email.toLowerCase() + ) { + await this.auth.setEmailVerified(connectedAccount.userId); + } return connectedAccount.user; }