Aglet

How to verify verification email recovery states

Verification should prove that every application-controlled verification state is legible and recoverable while keeping tokens private. Test both the first registration and a resend, then compare the resulting account and workspace path. External mailbox delivery may remain a separately marked boundary.

Check whether the outcome improved

  1. Test the pending path

    Register a synthetic account and assert the verification page explains what happened, what to do next, and whether resend or correction is available. Confirm no token, full address, or secret appears in HTML, redirects, logs, or screenshots used for review.

  2. Test link variants

    Use a valid fixture, a resent link, an expired link, an already-used link, and a malformed link. Assert each result has a safe destination and a clear message. Verify that successful verification proceeds to workspace naming without losing the registration context.

  3. Repeat interruption

    Refresh the pending page, close and reopen the browser, request resend, and return through the link after a delay. Assert one account is verified once and old links fail safely. Mark mailbox timing partial if the test environment cannot prove receipt.

What to carry forward

Accept when pending and link states provide safe, specific recovery, one account reaches the expected post-verification path, and no secret leaks. Keep delivery receipt as a separate partial result when it lies beyond the controlled test boundary.

Keep the decision with the work.

Use a Work Item in Aglet to record the problem, the evidence you have, and the next decision. Add an owner and priority, then keep updates in the discussion so the next person can follow the reasoning.

Create an account See the product workflow