Address 4 code-review findings in registration and login paths

FixSecurityService
Shipped
April 18, 2026 at 4:45 PM UTC
Author
Kamo
Commit
be2e3ec

- Hide raw exception message in /register 500 path; log instead - Fail-closed (503) on email-verified DB check failure in login - verifyEmailToken throws if user row is missing instead of silently no-oping - Move sendVerificationEmail outside @Transactional in register so the outbound HTTP call only fires after the token row is committed

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing