Turn your audience into a business. Publishing, memberships, subscriptions and newsletters.
Go to file
Simon Backx c6621dc17d
🐛 Updated support email verification flow (#15029)
refs https://github.com/TryGhost/Team/issues/584

The current support email verification flow uses an API endpoint as verification URL inside the emails. This is a bad pattern, and also has the side effect that it shows a JSON error if something goes wrong.

To fix this, this commit updates the whole flow to use the same pattern as newsletters:
- You can update the `members_support_address` setting directly via the edit endpoint of settings.
- Changes to that (and future 'guarded' email properties) are blocked and generate verification emails automatically.
- When an email verification has been sent, the meta property `sent_email_verification` is set.

Other changes:
- Underlying, the implementation of email verificaton has moved from the (old) members service to the settings BREAD service. This makes it easier to add extra email addresses in settings later on that are not related to 'members'.
- Now you can update the `members_support_address` by updating the settings directly, so the `updateMembersEmail` endpoint has been deprecated and is mapped to the new behaviour.
- The SingleUseTokenProvider threw a `UnauthorizedError` error if a token was expired or invalid. Those errors are caught by the admin app, and causes it to do a page reload (making the error message and modals invisible). To fix that, I've swapped it with a validation error.

Future changes:
- Existing emails that have been sent 24h before this change is applied, still use the `validateMembersEmailUpdate` API endpoint. This endpoint has not been removed for now, to not break those emails. In a future release, we should remove this.

Changes to admin: https://github.com/TryGhost/Admin/pull/2426
2022-07-15 14:43:52 +02:00
.github Update peter-evans/create-or-update-comment digest to b95e16d 2022-07-07 08:59:57 +02:00
content 🎨 Updated Casper to v5.2.0 2022-07-12 16:24:01 +01:00
core 🐛 Updated support email verification flow (#15029) 2022-07-15 14:43:52 +02:00
test 🐛 Updated support email verification flow (#15029) 2022-07-15 14:43:52 +02:00
.c8rc.json Reduced minimum required test coverage for functions 2022-07-12 10:24:02 +02:00
.editorconfig Removed Makefile settings from .editorconfig 2019-07-31 17:21:16 +08:00
.eslintignore Added new card src files to eslint ignore 2021-11-04 11:58:36 +00:00
.eslintrc.js Fixed straggling use of canary naming 2022-07-04 14:21:29 +02:00
.gitattributes Enforced unix line endings (#9871) 2018-10-23 10:59:09 +02:00
.gitignore Added minified ghost.min.css to gitignore 2022-03-22 10:44:39 +00:00
.gitmodules Renamed core/client to core/admin (#14837) 2022-05-17 08:27:13 +01:00
.npmignore Updated .npmignore 2022-07-12 14:09:01 +01:00
config.development.json Fixed indentation in config.development.json 2020-05-04 16:41:02 +02:00
ghost.js Added CLI command structure (#14821) 2022-05-17 15:40:12 +01:00
Gruntfile.js Renamed "client" references to "admin" 2022-05-17 09:05:44 +01:00
index.js Added new, simpler, linear boot process 2021-02-08 11:56:44 +00:00
jsconfig.json Renamed core/client to core/admin (#14837) 2022-05-17 08:27:13 +01:00
LICENSE 2022 2022-01-05 12:41:30 +00:00
loggingrc.js Simplified the config logic in loggingrc (#13751) 2021-11-16 15:00:11 +00:00
MigratorConfig.js Replaced ghost-version.js with @tryghost/version 2021-06-16 13:16:15 +01:00
package.json Update dependency sqlite3 to v5.0.9 2022-07-15 12:18:48 +01:00
PRIVACY.md Added UNPKG cdn to Privacy.md (#12964) 2021-10-21 10:24:28 +01:00
README.md Updated README 2022-05-23 13:06:35 +02:00
renovate.json 🐛 Fixed intermittent failures with embedding 2021-11-25 11:45:56 +01:00
SECURITY.md Updated ghost.org links 2021-01-19 13:28:36 +13:00
yarn.lock Update dependency sqlite3 to v5.0.9 2022-07-15 12:18:48 +01:00

 

Ghost Ghost

 

Ghost.orgForumDocsContributingTwitter

Downloads Latest release Build status Contributors

Love open source? We're hiring Node.js engineers to work on Ghost full-time.

 

Fiercely independent, professional publishing. Ghost is the most popular open source, headless Node.js CMS which already works with all the tools you know and love.

 

Ghost(Pro) Ghost(Pro)

The easiest way to get a production instance deployed is with our official Ghost(Pro) managed service. It takes about 2 minutes to launch a new site with worldwide CDN, backups, security and maintenance all done for you.

For most people this ends up being the best value option cause of how much time it saves — and 100% of revenue goes to the Ghost Foundation; funding the maintenance and further development of the project itself. So youll be supporting open source software and getting a great service!

If you prefer to run on your own infrastructure, we also offer official 1-off installs and managed support and maintenance plans via Ghost(Valet) - which can save a substantial amount of developer time and resources.

 

Quickstart install

If you want to run your own instance of Ghost, in most cases the best way is to use our CLI tool

npm install ghost-cli -g

 

Then, if installing locally add the local flag to get up and running in under a minute - Local install docs

ghost install local

 

or on a server run the full install, including automatic SSL setup using LetsEncrypt - Production install docs

ghost install

 

Check out our official documentation for more information about our recommended hosting stack & properly upgrading Ghost, plus everything you need to develop your own Ghost themes or work with our API.

Contributors & advanced developers

For anyone wishing to contribute to Ghost or to hack/customize core files we recommend following our full development setup guides: Contributor guideDeveloper setupAdmin App dev guide

 

Ghost sponsors

We'd like to extend big thanks to our sponsors and partners who make Ghost possible. If you're interested in sponsoring Ghost and supporting the project, please check out our profile on GitHub sponsors ❤️

DigitalOceanFastly

 

Getting help

You can find answers to a huge variety of questions, along with a large community of helpful developers over on the Ghost forum - replies are generally very quick. Ghost(Pro) customers also have access to 24/7 email support.

To stay up to date with all the latest news and product updates, make sure you subscribe to our blog — or you can always follow us on Twitter, if you prefer your updates bite-sized and facetious. 🎷🐢

 

Copyright & license

Copyright (c) 2013-2022 Ghost Foundation - Released under the MIT license. Ghost and the Ghost Logo are trademarks of Ghost Foundation Ltd. Please see our trademark policy for info on acceptable usage.