How to Setup Forced Email Verification in Auth0 - Auth0 Support

preview_player
Показать описание
In this video we are going to look at how to prevent users from logging into your app until they have verified their email address. 

___________________________________________
Learn with Auth0 by Okta
Follow Us on Social
Рекомендации по теме
Комментарии
Автор

This is such a common use case that it should be a setting in the Universal Login. If enabled it takes them to another built-in "Universal" ui to re-send verification email.

gatordog
Автор

Please, for the love of god, make this a setting in the Universal Login.

ross
Автор

Here a year later, and my goodness, still getting 400 error until verification message. Absolute insanity guys

manomancan
Автор

This is really disappointing, Its 2024 and there still isn't a built in email verification for login for an enterprise product

MuhammadShahrukh-zk
Автор

Genuinely though, the fact that this is a frequently asked question but you haven't yet added the functionality to the universal login is really lame. Auth0 cut Oktas lunch (until they got brought) by simplifying a similar product. I suspect soon the time will come that the same happens to Auth0.

popeye
Автор

how to enable verify using code in auth0?

allenvarshney
Автор

This is so basic. Should have that natively. At least I can rest knowing I didn't suggest this product to the team. Terrible DX.

saint_michael_the_archangel
Автор

This is the first time I've been so disappointed in a tutorial that I felt the need to write a response. You end this video by stating you can resend the verification email by using the management API, but fail to say that it can only be done in the action since the app will not have access to the user information due to the logging in stopping before they are authenticated, which is exactly what I was hoping to find out with this waste of time you call a video.

mina-yixz
Автор

You guys have a logic problem in here, I believe. Scenario: I want to change my email address from the user profile, I enter a new email address but type it wrong, confirmation email goes to someone else or no where. The main problem here is not verifying the new email address by clicking the link but toyed user can’t use their current email address to login. With a malicious user, it’s even worse. Haven’t tried but they can even change the password I think.

Correct flow should be like this; enter your new email address, call the api to send email verification link via email, at this point without clicking the link, the old email should be used/allowed for login, click the link to verify new email address and then you should not be allowed to use the old email address and you only login with your the new one.

Hoytttat