From 54ed4e3b7868059e0456d44bb2be8c56d490526d Mon Sep 17 00:00:00 2001 From: Vojtech Knaisl Date: Sun, 23 Aug 2026 07:24:52 +0200 Subject: [PATCH 1/2] Fix consent handling in OpenID login flow --- .../OpenId/Client/Flow/OpenIdClientFlowService.hs | 9 ++++++++- wizard-server/src/Wizard/Service/User/UserService.hs | 6 ++++++ 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/wizard-server/src/Wizard/Service/OpenId/Client/Flow/OpenIdClientFlowService.hs b/wizard-server/src/Wizard/Service/OpenId/Client/Flow/OpenIdClientFlowService.hs index 080327bb8..d0f207575 100644 --- a/wizard-server/src/Wizard/Service/OpenId/Client/Flow/OpenIdClientFlowService.hs +++ b/wizard-server/src/Wizard/Service/OpenId/Client/Flow/OpenIdClientFlowService.hs @@ -22,6 +22,7 @@ import Shared.OpenId.Api.Resource.OpenId.Client.Flow.OpenIdClientAuthenticationU import Shared.OpenId.Model.OpenId.OpenIdClientParameter import Shared.OpenId.Service.OpenId.Client.Flow.OpenIdClientFlowService import Shared.OpenId.Service.OpenId.Client.Flow.OpenIdClientFlowUtil (parseIdToken) +import Shared.UserEmailLink.Model.UserEmailLink.UserEmailLink import Wizard.Database.DAO.Common import Wizard.Database.DAO.OpenId.OpenIdClientSessionDAO import Wizard.Database.DAO.User.UserDAO @@ -32,10 +33,12 @@ import Wizard.Model.Context.AppContextHelpers import Wizard.Model.OpenId.OpenIdClientSession import Wizard.Model.User.User import Wizard.Model.User.UserRegistrationPendingServiceType +import Wizard.Model.UserEmailLink.UserEmailLinkType import Wizard.Service.Tenant.Config.ConfigService import Wizard.Service.Tenant.TenantHelper import Wizard.Service.User.UserService import Wizard.Service.User.UserUtil +import Wizard.Service.UserEmailLink.UserEmailLinkService import Wizard.Service.UserToken.Login.LoginService import Wizard.Service.UserToken.Login.LoginValidation (validateIsUserActive) import WizardLib.Public.Api.Resource.UserToken.UserTokenDTO @@ -126,7 +129,11 @@ loginUser providerUuid mClientUrl _mError mCode mState mIdToken mUserAgent mSess (Just email, Just firstName, Just lastName) -> do consentRequired <- isConsentRequired Nothing user <- createUserFromOpenIdLogin openIdClient externalId firstName lastName email mPicture mUserUuid (not consentRequired) - createLoginToken user mUserAgent mSessionState + if consentRequired + then do + userEmailLink <- createUserEmailLink user.uuid ConsentsRequiredUserEmailLinkType user.tenantUuid + return $ ConsentsRequiredDTO {hash = userEmailLink.hash} + else createLoginToken user mUserAgent mSessionState _ -> do pending <- upsertPendingExternalRegistration OpenIdUserRegistrationPendingServiceType providerUuid externalId Nothing mEmail mFirstName mLastName mPicture Nothing return $ diff --git a/wizard-server/src/Wizard/Service/User/UserService.hs b/wizard-server/src/Wizard/Service/User/UserService.hs index 7964a03fa..93db9ecd0 100644 --- a/wizard-server/src/Wizard/Service/User/UserService.hs +++ b/wizard-server/src/Wizard/Service/User/UserService.hs @@ -295,6 +295,12 @@ changeUserState hash active = , emailVerifiedAt = Just now , emailPending = Nothing } + (ConsentsRequiredUserEmailLinkType, Just pendingEmail) -> + baseUser + { email = pendingEmail + , emailVerifiedAt = Just now + , emailPending = Nothing + } _ -> baseUser updateUserByUuid updatedUser void $ deleteUserEmailLinkByHash userEmailLink.hash From d7e94d0b1ddcefa15248b6034ce8505ef6fbf5c1 Mon Sep 17 00:00:00 2001 From: Vojtech Knaisl Date: Sun, 23 Aug 2026 07:41:42 +0200 Subject: [PATCH 2/2] Release 4.33.4 --- registry-public/package.yaml | 2 +- registry-server/package.yaml | 2 +- registry-server/src/Registry/Api/Handler/Swagger/Api.hs | 2 +- shared-common/package.yaml | 2 +- wizard-public/package.yaml | 2 +- wizard-server/package.yaml | 2 +- wizard-server/src/Wizard/Api/Handler/Swagger/Api.hs | 2 +- 7 files changed, 7 insertions(+), 7 deletions(-) diff --git a/registry-public/package.yaml b/registry-public/package.yaml index 180eb8e8a..d8def6332 100644 --- a/registry-public/package.yaml +++ b/registry-public/package.yaml @@ -1,5 +1,5 @@ name: registry-public -version: '4.33.3' +version: '4.33.4' synopsis: Registry Public description: Registry Public category: Web diff --git a/registry-server/package.yaml b/registry-server/package.yaml index 03721be6c..5b09011a4 100644 --- a/registry-server/package.yaml +++ b/registry-server/package.yaml @@ -1,5 +1,5 @@ name: registry-server -version: '4.33.3' +version: '4.33.4' synopsis: Engine Registry description: Engine Registry category: Web diff --git a/registry-server/src/Registry/Api/Handler/Swagger/Api.hs b/registry-server/src/Registry/Api/Handler/Swagger/Api.hs index 02f502fef..819dca47c 100644 --- a/registry-server/src/Registry/Api/Handler/Swagger/Api.hs +++ b/registry-server/src/Registry/Api/Handler/Swagger/Api.hs @@ -41,7 +41,7 @@ swagger = s._swaggerInfo { _infoTitle = "Registry API" , _infoDescription = Just "API specification for Registry" - , _infoVersion = "4.33.3" + , _infoVersion = "4.33.4" , _infoLicense = Just $ License diff --git a/shared-common/package.yaml b/shared-common/package.yaml index d5082d900..e1a4b552a 100644 --- a/shared-common/package.yaml +++ b/shared-common/package.yaml @@ -1,5 +1,5 @@ name: shared-common -version: '4.33.3' +version: '4.33.4' synopsis: Engine Shared description: Engine Shared category: Web diff --git a/wizard-public/package.yaml b/wizard-public/package.yaml index 09202393f..6d0a5f565 100644 --- a/wizard-public/package.yaml +++ b/wizard-public/package.yaml @@ -1,5 +1,5 @@ name: wizard-public -version: '4.33.3' +version: '4.33.4' synopsis: Wizard Public description: Wizard Public category: Web diff --git a/wizard-server/package.yaml b/wizard-server/package.yaml index 996923ac5..15e46e5eb 100644 --- a/wizard-server/package.yaml +++ b/wizard-server/package.yaml @@ -1,5 +1,5 @@ name: wizard-server -version: '4.33.3' +version: '4.33.4' synopsis: Engine Wizard description: Engine Wizard category: Web diff --git a/wizard-server/src/Wizard/Api/Handler/Swagger/Api.hs b/wizard-server/src/Wizard/Api/Handler/Swagger/Api.hs index e37be04f2..9351d3d53 100644 --- a/wizard-server/src/Wizard/Api/Handler/Swagger/Api.hs +++ b/wizard-server/src/Wizard/Api/Handler/Swagger/Api.hs @@ -158,7 +158,7 @@ swagger = s._swaggerInfo { _infoTitle = "Wizard API" , _infoDescription = Just "API specification for Wizard" - , _infoVersion = "4.33.3" + , _infoVersion = "4.33.4" , _infoLicense = Just $ License