Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Unique, case-insensitive index on user email — detect and report duplicates first, then migrate

Open
#809 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
sql, typescript

Research direction

Start with packages/db/src/schema/auth.ts and trace the existing Better Auth sign-up and adapter paths. Add the read-only duplicate check and doctor reporting, document operator remediation, then add the guarded unique-index migration and matching error handling. Use the requested parallel sign-up tests to verify that every path creates exactly one user.

Written by the indexing model from the issue text.

Description

self-serve-cloud

Problem

The Better Auth user table (packages/db/src/schema/auth.ts) has no unique index on email. The security review of #805 reproduced the consequence: 8 parallel sign-ups on one email all landed, creating 8 user rows for the same address. #805 closes that for the claim path with an atomic, persisted claim row (agentdash_box_claim), but ordinary sign-up paths (company invites, open sign-up on self-hosted installs, SSO) still rely on Better Auth's check-then-insert, which is not atomic.

Why not just add the index

Existing installs (MKThink's mkboard, the runner at :3199, self-hosters) may already hold duplicate or case-variant emails. A migration that creates a unique index would fail on upgrade and block the release.

Proposal

  1. A read-only check, first (script and a doctor check): report duplicate emails compared case-insensitively (lower(email)), with user ids, creation dates and memberships, on every known instance.
  2. A documented remediation for any duplicates found (merge or rename, done by an operator per instance, never automatically).
  3. Then a migration adding CREATE UNIQUE INDEX CONCURRENTLY … ON "user" (lower(email)), guarded so it refuses with a clear message (not a failed boot) if duplicates remain, plus the matching change in Better Auth's adapter usage so the unique violation surfaces as "email already registered".
  4. Tests: parallel sign-ups on one email create exactly one user on every path.

Filed from the #805 security review (claim-link race). Out of scope for #805 on purpose.

Dominant language
TypeScript
Stars
0
Forks
0
Avg merge
1d 13h
Merged PRs (30d)
167

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from thetangstr/agentdash

All issues in thetangstr/agentdash

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.