Unique, case-insensitive index on user email — detect and report duplicates first, then migrate
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- sql, typescript
- Domain
- authentication, database, testing
Research direction
Start with packages/db/src/schema/auth.ts and trace the existing Better Auth sign-up and adapter paths. Add the read-only duplicate check and doctor reporting, document operator remediation, then add the guarded unique-index migration and matching error handling. Use the requested parallel sign-up tests to verify that every path creates exactly one user.
Written by the indexing model from the issue text.
Description
Problem
The Better Auth user table (packages/db/src/schema/auth.ts) has no unique index on email. The security review of #805 reproduced the consequence: 8 parallel sign-ups on one email all landed, creating 8 user rows for the same address. #805 closes that for the claim path with an atomic, persisted claim row (agentdash_box_claim), but ordinary sign-up paths (company invites, open sign-up on self-hosted installs, SSO) still rely on Better Auth's check-then-insert, which is not atomic.
Why not just add the index
Existing installs (MKThink's mkboard, the runner at :3199, self-hosters) may already hold duplicate or case-variant emails. A migration that creates a unique index would fail on upgrade and block the release.
Proposal
- A read-only check, first (script and a doctor check): report duplicate emails compared case-insensitively (
lower(email)), with user ids, creation dates and memberships, on every known instance. - A documented remediation for any duplicates found (merge or rename, done by an operator per instance, never automatically).
- Then a migration adding
CREATE UNIQUE INDEX CONCURRENTLY … ON "user" (lower(email)), guarded so it refuses with a clear message (not a failed boot) if duplicates remain, plus the matching change in Better Auth's adapter usage so the unique violation surfaces as "email already registered". - Tests: parallel sign-ups on one email create exactly one user on every path.
Filed from the #805 security review (claim-link race). Out of scope for #805 on purpose.
- Dominant language
- TypeScript
- Stars
- 0
- Forks
- 0
- Avg merge
- 1d 13h
- Merged PRs (30d)
- 167
Getting set up
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from thetangstr/agentdash
-
owner:devin P3 security server
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
thetangstr/agentdash#811 ·
Maintainers usually reply within 1 day
-
owner:devin P3 ui ux-sharpening
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
thetangstr/agentdash#806 ·
Maintainers usually reply within 1 day
-
good first issue owner:titus P3 server triaged ui
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
thetangstr/agentdash#171 · 2 comments ·
Maintainers usually reply within 1 day
-
mvl-1.0 owner:orchestrator self-serve-cloud
Difficulty 5/5 Over a week Newbie friendliness 42/100
thetangstr/agentdash#838 ·
Maintainers usually reply within 1 day
-
bug owner:orchestrator P2 release
Difficulty 5/5 Over a week Newbie friendliness 35/100
thetangstr/agentdash#833 · 2 comments ·
Maintainers usually reply within 1 day
All issues in thetangstr/agentdash
Similar issues
-
priority: P2
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
prime-radiant-inc/evener#3291 ·
Maintainers usually reply within 1 day
-
accessibility bug revealjs
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
quarto-dev/quarto-cli#14961 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
supabase/agent-skills#614 ·
-
Content
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
RunestoneInteractive/rs#1559 · 1 comment ·
Maintainers usually reply within 2 days