(Djoser) Weird activation email when I update the user fields

Viewed 399

Every time when I try to update my user with the PATCH method to the /users/me/ endpoint, an activation email is always sent. The user is already active in the system... so I don't know what is happening.

SEND_ACTIVATION_EMAIL is True, but I understand that the email will be sent only after: creating an account or updating their email (I'm not updating the email)

DJOSER = {
    ....
    'ACTIVATION_URL': 'auth/users/activation/{uid}/{token}',
    'SEND_ACTIVATION_EMAIL': True,
    ....
}
1 Answers

I have the same issue. This is due to the djoser.views.UserViewSet.perform_update method.

    def perform_update(self, serializer):
    super().perform_update(serializer)
    user = serializer.instance
    #should we send activation email after update?
    if settings.SEND_ACTIVATION_EMAIL:
        context = {"user": user}
        to = [get_user_email(user)]
        settings.EMAIL.activation(self.request, context).send(to)

As you can see, even if you use email as a login field, you keep getting email confirmation if you update any field. This is not the right thing to do. This should be done only if the email has changed.

In your case the update part should be omitted:

#user = serializer.instance
#should we send activation email after update?    
#if settings.SEND_ACTIVATION_EMAIL:
        #context = {"user": user}
        #to = [get_user_email(user)]
        #settings.EMAIL.activation(self.request, context).send(to)
Related