defmodule PhoenixKitWeb.Users.Confirmation do @moduledoc """ LiveView for email confirmation. Handles the email confirmation flow after a user clicks the confirmation link from their registration email. Validates the confirmation token and confirms the user account. """ use PhoenixKitWeb, :live_view alias PhoenixKit.Users.Auth alias PhoenixKit.Utils.Routes def mount(%{"token" => token}, _session, socket) do form = to_form(%{"token" => token}, as: "user") {:ok, assign(socket, form: form), temporary_assigns: [form: nil]} end # Do not log in the user after confirmation to avoid a # leaked token giving the user access to the account. def handle_event("confirm_account", %{"user" => %{"token" => token}}, socket) do case Auth.confirm_user(token) do {:ok, _} -> {:noreply, socket |> put_flash(:info, "User confirmed successfully.") |> redirect(to: "/")} :error -> # If there is a current user and the account was already confirmed, # then odds are that the confirmation link was already visited, either # by some automation or by the user themselves, so we redirect without # a warning message. case socket.assigns do %{phoenix_kit_current_user: %{confirmed_at: confirmed_at}} when not is_nil(confirmed_at) -> {:noreply, redirect(socket, to: "/")} %{} -> {:noreply, socket |> put_flash(:error, "User confirmation link is invalid or it has expired.") |> redirect(to: "/")} end end end end