-
Bug
-
Resolution: Unresolved
-
Normal
-
None
-
None
-
None
The whole resend-verification code was added in 2011 (MBS-3188) apparently under the incorrect assumption that we store the email a user has entered before it gets verified. In fact, we only store the email as part of the verification process - so there's no possible case where we would have an email stored that still needs verifying. The entirety of the resend-verification code is as such completely useless, since there's no reason to re-verify an already verified email address.
Original text:
Apart from visibility , resend link actually works and resend a mail to verifes user, that should not be the case .
I think backend should check if the user is verified before sending mail again.