nextcloud / nextcloud/registration
email addresses with "+" get stuck in registration (or other forbidden characters)
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 147
- Forks
- 83
- Avg merge
- 1d 2h
- Merged PRs (30d)
- 9
Description
When registering an email with a + in the address, the registration gets stuck when setting a password after verifying the email address.
This is because of the setting:
Administration settings -> Registration -> User settings -> Force email as login name
Related: server#21313 Allowed characters in username/userid
Steps to reproduce
- open Nextcloud in browser
- click
Register - Enter an email you own with a
+character. E.g.your.name+something@gmail.com(GMail forwards mails to arbitrary prefixes behind a+for existing addresses) - enter the verification code you got via mail
- try to set a passwort
Expected behaviour
Users should be able to register, regardless which characters their email addresses contain.
I guess the best solution in line with the Force email as login name policy would be to somehow automatically derive a valid username.
E.g. for first.last+something@example.org the + could be replaced with a _.
Just add a strategy for possible collisions. In case a user first.last+something@example.org and a user first.last_something@example.org register. (first the + and second the _, and also the other way around)
Actual behaviour
Only the following characters are allowed in a username: "a-z", "A-Z", "0-9", spaces and "_.@-'"
There's no input field to set another username.
There's only the password input field and a disabled input field which shows the registered email address.
Server configuration
Web server: Apache (all Debian-12 default software)
Nextcloud version: 28 and 29 tested
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the registration flow with an email containing a + while Force email as login name is enabled, then trace where the username validation blocks password setup. Review the proposed username-derivation and collision cases; done means valid email addresses can complete registration without creating ambiguous usernames.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- authentication
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100