4966fb4582e90c758a94961a9df521434b66d941
gperez2
Fri Sep 18 15:08:08 2026 -0700
Updating hgLogin's CILogon-unverified-email wording (choose a username page, address-collision message, and new-account confirmation) for clarity and consistency, refs #38339
Co-Authored-By: Claude Sonnet 5 You signed in with %s, and %s does not tell us whether the email "
- "address it gave us really belongs to you, so we asked you for one. No %s "
- "account uses %s yet, so we are making a new account for it. Confirming "
- "the address is the last step.
You signed in with %s, and %s did not tell us an email address, so we " "asked you for one. No %s account uses %s yet, so we are making a new " "account for it. Confirming the address is the last step.
", encProvider, encProvider, brwName, encAddress); } else { char *encUser = htmlEncode(existingUser); /* Say that the address was changed. Without this the page comes back looking exactly * as it did before the change, the new address being the only sign anything happened. */ if (justChanged) hPrintf("The email address on the %s account %s is now %s.
", brwName, encUser, encAddress); @@ -2522,34 +2521,34 @@ * sign-in lands here, which surprised real users (#38341). Keyed on whether an address arrived, * not on the provider's name: a mirror can call a provider anything it likes in hg.conf, so a * name test would silently miss it (#38213). * Test whether anything arrived, not whether oauthProviderEmail() accepted it. A provider that * sends an address we cannot use -- spc_email_isvalid rejects every byte >= 127, so any * non-ASCII address -- also leaves us asking for one, but telling that user the provider shares * no address would be simply untrue. * Same for a provider that did release an address which we then dropped because it would not * say the address is verified: CILogon does exactly this, and "does not share your email * address with us" was plainly wrong for it (#38339). */ char *unverified = oauthUnverifiedEmail(); if (isEmpty(email) && unverified != NULL) { char *encUnverified = htmlEncode(unverified); hPrintf("%s gave us the email address %s, but does not tell us whether that " - "address really belongs to you, so we cannot use it to sign you in to an account that " - "already has it. Enter an address below and confirm it once; after that this sign-in " - "will work on its own. If you already have an account, use another sign-in option " - "instead.
", label, encUnverified); + "address belongs to you. So we cannot use it to sign you in, even if an account " + "already has this address. Enter your email address below. Once it is confirmed, %s " + "will sign you in directly. If you already have an account, use another sign-in " + "option instead.", label, encUnverified, label); freeMem(encUnverified); } else if (isEmpty(email)) hPrintf("A new %s account is created for any %s sign-in we have not seen before, because " "%s does not share your email address with us. So you cannot sign in to an existing " "account this way. Use another sign-in option if you do not want to create a new " "account.
", brwName, label, label); else if (providerEmail == NULL) hPrintf("We cannot use the email address %s gave us, so please enter one below.
", label); printUsernameNote(); hPrintf("%s", errMsg ? errMsg : ""); hPrintf("