Skip to content

Add EmailVerification.DisableNotifyUnlockState as a connector property - #1161

Merged
sadilchamishka merged 1 commit into
wso2-extensions:masterfrom
sadilchamishka:fix/tenant-scoped-unlock-notification-on-email-verification
Sep 24, 2026
Merged

sadilchamishka merged 1 commit into
wso2-extensions:masterfrom
sadilchamishka:fix/tenant-scoped-unlock-notification-on-email-verification

Conversation

@sadilchamishka

@sadilchamishka sadilchamishka commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Issue

EmailVerification.DisableNotifyUnlockState suppresses the account unlock email sent when a user confirms email verification, but it is only readable from the server level identity.xml. It cannot be configured per tenant.

Fix

Register the property on the email verification connector so it resolves through IdentityGovernanceService per tenant. The identity.xml value seeds the connector default, so deployments that only set the server level property keep their current behaviour.

The consumer of this property is in the account lock handler; that change is sent separately.

Testing

org.wso2.carbon.identity.recovery suite: 526 tests, 0 failures. UserEmailVerificationConfigImplTest updated for the new property.

Summary by CodeRabbit

  • New Features
    • Added a configurable option to disable the account unlock email sent after email verification.
    • The option is available in the user email verification connector and defaults to disabled.

The account unlock notification suppression for the email verification
flow was only configurable through the server level identity.xml
property, which cannot be set per tenant.

Expose it on the email verification connector so it can be configured
per tenant. The identity.xml value seeds the connector default, so
deployments that only set the server level property keep their current
behaviour.
@coderabbitai

coderabbitai Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 04d4fcd6-a021-4787-91bb-7fcc877a5978

📥 Commits

Reviewing files that changed from the base of the PR and between 230dd27 and 495db21.

📒 Files selected for processing (3)
  • components/org.wso2.carbon.identity.recovery/src/main/java/org/wso2/carbon/identity/recovery/IdentityRecoveryConstants.java
  • components/org.wso2.carbon.identity.recovery/src/main/java/org/wso2/carbon/identity/recovery/connector/UserEmailVerificationConfigImpl.java
  • components/org.wso2.carbon.identity.recovery/src/test/java/org/wso2/carbon/identity/recovery/connector/UserEmailVerificationConfigImplTest.java

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The change adds the EmailVerification.DisableNotifyUnlockState boolean connector property. It exposes the property metadata, reads configured values, defaults to false, and extends unit tests for the new mappings.

Changes

Email verification configuration

Layer / File(s) Summary
Connector property wiring
components/org.wso2.carbon.identity.recovery/src/main/java/.../IdentityRecoveryConstants.java, components/org.wso2.carbon.identity.recovery/src/main/java/.../UserEmailVerificationConfigImpl.java
Adds the configuration key and wires its display name, description, property list entry, default value, configured value, and boolean metadata.
Configuration mapping tests
components/org.wso2.carbon.identity.recovery/src/test/java/.../UserEmailVerificationConfigImplTest.java
Tests the new property name, description, property list entry, and default value.

Priority: ⬇️ Low — Defer this narrow connector-configuration change because it adds one optional email-verification property while preserving existing behavior.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 495db

This adds a tenant-configurable email-verification setting to suppress the account-unlock email, while retaining the existing false default. The configuration wiring and expected defaults are covered with no concrete current-head merge risk identified.

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description clearly explains the issue, fix, compatibility behavior, and unit-test results. However, it omits most required template sections, including purpose, goals, approach, user stories, rel… Complete the required template sections. Enter N/A with a reason where a section does not apply, and provide the mandatory Developer Checklist status and security-check responses.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 3 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the main change: adding EmailVerification.DisableNotifyUnlockState as a connector property.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description clearly explains the issue, fix, compatibility behavior, and unit-test results. However, it omits most required template sections, including purpose, goals, approach, user stories, release note, documentation, security checks, and test environment.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

UserEmailVerificationConfigImpl.getMetaData() is inconsistent with the exposed property set (missing metadata for an existing exposed property), which should be corrected alongside this update.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR registers EmailVerification.DisableNotifyUnlockState as an email verification connector property so it can be resolved per-tenant via IdentityGovernanceService, while seeding the connector default from the existing server-level identity.xml value for backward compatibility.

Changes:

  • Added EmailVerification.DisableNotifyUnlockState to IdentityRecoveryConstants.ConnectorConfig.
  • Registered the new property in UserEmailVerificationConfigImpl (names, descriptions, property list, default seeding, and metadata).
  • Updated UserEmailVerificationConfigImplTest expectations to include the new property.
File summaries
File Description
components/org.wso2.carbon.identity.recovery/src/test/java/org/wso2/carbon/identity/recovery/connector/UserEmailVerificationConfigImplTest.java Updates connector config tests to include the new property in mappings, names, and defaults.
components/org.wso2.carbon.identity.recovery/src/main/java/org/wso2/carbon/identity/recovery/IdentityRecoveryConstants.java Adds the new connector config key constant for per-tenant governance resolution.
components/org.wso2.carbon.identity.recovery/src/main/java/org/wso2/carbon/identity/recovery/connector/UserEmailVerificationConfigImpl.java Registers the property across mappings/defaults and exposes it for tenant configuration.
Review details
  • Files reviewed: 3/3 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@codecov

codecov Bot commented Sep 8, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 60.00000% with 4 lines in your changes missing coverage. Please review.
✅ Project coverage is 55.34%. Comparing base (adfdfd7) to head (495db21).
⚠️ Report is 3 commits behind head on master.

Files with missing lines Patch % Lines
...ery/connector/UserEmailVerificationConfigImpl.java 60.00% 3 Missing and 1 partial ⚠️
Additional details and impacted files
@@            Coverage Diff            @@
##             master    #1161   +/-   ##
=========================================
  Coverage     55.34%   55.34%           
  Complexity     3346     3346           
=========================================
  Files           317      317           
  Lines         22166    22176   +10     
  Branches       4585     4586    +1     
=========================================
+ Hits          12267    12273    +6     
- Misses         8323     8326    +3     
- Partials       1576     1577    +1     
Flag Coverage Δ
unit 45.56% <60.00%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@jenkins-is-staging

Copy link
Copy Markdown

PR builder started
Link: https://github.com/wso2/product-is/actions/runs/34234008657

@jenkins-is-staging

Copy link
Copy Markdown

PR builder completed
Link: https://github.com/wso2/product-is/actions/runs/34234008657
Status: failure

@sadilchamishka

Copy link
Copy Markdown
Contributor Author

Integration test note: the product-is integration run for this PR fails on IdentityGovernanceSuccessTest.testSearchGovernanceConnectorProperties, which asserts the email verification connector's properties positionally.

properties[12].name  Expected: EmailVerification.ExpiryTime
                     Actual:   EmailVerification.DisableNotifyUnlockState

Adding a property at index 12 shifts the later entries. Companion PR with the expected-response update: wso2/product-is#28428.

The two cannot both be green at the same time — a product-is PR is built against the released identity-governance version, so #28428 stays red until this one is merged and released. Suggested order: this PR first, then #28428 once the version is bumped.

(The assertion is order-fragile independently of this change — it passed on 2 of its 4 invocations in the original run. Making it order-independent looks worthwhile as a separate change.)

@jenkins-is-staging

Copy link
Copy Markdown

PR builder started
Link: https://github.com/wso2/product-is/actions/runs/34460712093

@jenkins-is-staging

Copy link
Copy Markdown

PR builder completed
Link: https://github.com/wso2/product-is/actions/runs/34460712093
Status: failure

@sadilchamishka
sadilchamishka merged commit df98ee6 into wso2-extensions:master Sep 24, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants