Repository navigation
Fix unresolved password recovery email placeholders - #1162
thuvarahan-t wants to merge 1 commit into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughChangesRecovery notification properties
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to Recovery emails now receive empty values for omitted optional properties while preserving supplied values. The change is ready to merge. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Purpose
Addresses wso2/product-is#28439.
Password recovery emails could contain unresolved
{{sp}}and{{callback}}placeholders when those optional properties were not included in the password recovery initiation request.Goals
Ensure optional
spandcallbacktemplate properties resolve safely when omitted, while preserving supplied values and existing callback validation.Approach
NotificationPasswordRecoveryManagerpreviously copied only non-blank request metadata into the notification event. Whensporcallbackwas absent, the property was missing entirely and the template engine could leave the placeholder unresolved.This change:
sp.spandcallbackproperties withputIfAbsent.User stories
As a user receiving a password recovery email, I should not see unresolved optional-property placeholders when the initiation request omits
sporcallback.Developer Checklist (Mandatory)
product-isissue to track any behavioral change or migration impact.Release note
Prevent unresolved service-provider and callback placeholders in password recovery emails when those optional values are omitted.
Documentation
N/A - this corrects notification template property resolution without changing public APIs or documented configuration.
Training
N/A - no training content impact.
Certification
N/A - no certification exam impact.
Marketing
N/A - no marketing content impact.
Automation tests
spandcallbacksupplied and missing states.NotificationPasswordRecoveryManagerTest: 15 passed.org.wso2.carbon.identity.recoverymodule: 530 passed.git diff --check: passed.SpotBugs reports existing unrelated findings; none are introduced on the changed lines.
Security checks
Samples
N/A - no sample changes are required.
Related PRs
N/A.
Migrations (if applicable)
N/A - no migration is required.
Test environment
Local development environment using the repository's Maven test configuration.
Learning
Reviewed the password recovery notification metadata flow and existing template-property behavior.
Summary by CodeRabbit