Open
Description
Preconditions and environment
- Latest Version
- Customers are receiving multiple confirmation emails if they repeatedly request the confirmation link. Currently, there are no rate limits in place to prevent this behavior.
Steps to reproduce
Enable Email Confirmation required for customer signup
Create a customer account
Go to customer confirmation link page(/customer/account/confirmation)
Try request multiple confirmation link for the same email
Expected result
we should implement rate limiting to restrict how many times a user can request a confirmation email within a given timeframe. This will help reduce email spam and improve user experience.
Actual result
Multiple confirmation email being sent to registered email
Triage and priority
- Severity: S0 - Affects critical data or functionality and leaves users without workaround.Severity: S1 - Affects critical data or functionality and forces users to employ a workaround.Severity: S2 - Affects non-critical data or functionality and forces users to employ a workaround.Severity: S3 - Affects non-critical data or functionality and does not force users to employ a workaround.Severity: S4 - Affects aesthetics, professional look and feel, “quality” or “usability”.
Metadata
Metadata
Assignees
Type
Projects
Status
Pull Request in Progress
Activity
m2-assistant commentedon Apr 15, 2025
Hi @Mohamed-Asar. Thank you for your report.
To speed up processing of this issue, make sure that the issue is reproducible on the vanilla Magento instance following Steps to reproduce.
@magento I am working on this
Join Magento Community Engineering Slack and ask your questions in #github channel.
⚠️ According to the Magento Contribution requirements, all issues must go through the Community Contributions Triage process. Community Contributions Triage is a public meeting.
🕙 You can find the schedule on the Magento Community Calendar page.
📞 The triage of issues happens in the queue order. If you want to speed up the delivery of your contribution, join the Community Contributions Triage session to discuss the appropriate ticket.
m2-assistant commentedon Apr 15, 2025
Hi @engcom-Bravo. Thank you for working on this issue.
In order to make sure that issue has enough information and ready for development, please read and check the following instruction: 👇
Area: XXXXX
label to the ticket, indicating the functional areas it may be related to.2.4-develop
branchDetails
- If the issue is reproducible on2.4-develop
branch, please, add the labelReproduced on 2.4.x
.- If the issue is not reproducible, add your comment that issue is not reproducible and close the issue and stop verification process here!
Issue: Confirmed
once verification is complete.Mohamed-Asar commentedon Apr 15, 2025
@magento i'm working on this
[-]Rate limit not available customer email confirmation email[/-][+]Rate limit not available for customer confirmation link email[/+]engcom-Bravo commentedon Apr 16, 2025
Hi @Mohamed-Asar,
Thanks for your reporting and collaboration.
To proceed further marking this as
Feature Request
.Thanks.