# Phantom aanmeldingen (twee gebruikers met hetzelfde account na migratie)

**URL:** https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631
**Category:** Support
**Created:** [29 oktober 2020 om 13:06 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631 "2020-10-29T13:06:04Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Paul\_King](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paul_king/32/165426_2.png) [@Paul\_King](https://meta.discourse.org/u/Paul_King)
#### Post date: [29 oktober 2020 om 13:06 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/1 "2020-10-29T13:06:04Z")

</div>

Hi, I have had a problem that began several Discourse updates ago, with getting notifications that a new user is waiting for approval, only to find that the review queue is empty.

This only occurs when a single user is requesting approval. If multiple people are waiting, I can see all but one in the queue - but one is always not included.

A lot of people have been unable to sign up in other words.

In a separate [thread](https://meta.discourse.org/t/emailed-administrator-notification-new-users-awaiting-approval/148335/10) it was suggested that the multi-select plugin might be somehow involved and causing Discourse to add one to the queue length.

On balance this seems unlikely, in that something must be occurring to trigger a notification on some days and not others. Also the issue did not begin when the plugin was installed - it commenced some months later, and I can only correlate this to a discourse update (since I don’t believe any another plugins or changes have been made since)

Has anyone else experienced this? And what might the solution be?

On the off chance, @jjaffeux is it possible the “FIX: makes value parsing more resilient” amendment you made to this plugin could be implicated this issue?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [31 oktober 2020 om 22:04 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/2 "2020-10-31T22:04:28Z")

</div>

So is this plugin related or based on core discourse functionality only? I’m unclear.

---

<div class="post-metadata">

### Author: ![Paul\_King](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paul_king/32/165426_2.png) [@Paul\_King](https://meta.discourse.org/u/Paul_King)
#### Post date: [1 november 2020 om 02:44 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/3 "2020-11-01T02:44:53Z")

</div>

Hi - I am unclear as well, Could it be both?  
The issue did not start when the plugin was first installed, but began a few core updates ago. If the plugin is involved at all, perhaps there is some unintended interaction?

I can’t really test uninstalling the plugin to see if the issue continues, as it is mission critical - vetting of user sign ups is dependent on the answers they can only provide with this plug-in active (users need to make selections from a drop down list).

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2 november 2020 om 05:17 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/4 "2020-11-02T05:17:00Z")

</div>

[GitHub - procourse/discourse-multiselect-user-field · GitHub](https://github.com/procourse/discourse-multiselect-user-field) should not really be a plugin, it only includes JavaScript.

I guess my first recommendation here would be to wait for the “bad state” … then enable [safe mode](https://meta.discourse.org/t/53504?silent=true) for your browser and see if the queue looks good.

> [@Using Safe Mode to troubleshoot issues with themes and plugins](https://meta.discourse.org/t/how-to-use-discourse-safe-mode/53504):
>
> bookmark This guide explains how to use Discourse’s [Safe Mode](https://meta.discourse.org/t/53504?silent=true) to troubleshoot issues with themes and plugins. person_raising_hand Required user level: All users Discourse offers a “JavaScript [Safe Mode](https://meta.discourse.org/t/53504?silent=true)” that allows any user to isolate the root cause of JavaScript issues caused by plugins, themes, or theme components. This feature is particularly useful for troubleshooting problems on your Discourse site. Accessing [Safe Mode](https://meta.discourse.org/t/53504?silent=true) To access [Safe Mode](https://meta.discourse.org/t/53504?silent=true), follow these steps: Open a new browse…

If it looks good in [safe mode](https://meta.discourse.org/t/53504?silent=true) you probably want to post on #Marketplace to get the plugin converted to a theme component and updated to latest patterns from Discourse.

---

<div class="post-metadata">

### Author: ![Paul\_King](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paul_king/32/165426_2.png) [@Paul\_King](https://meta.discourse.org/u/Paul_King)
#### Post date: [2 november 2020 om 05:37 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/5 "2020-11-02T05:37:32Z")

</div>

Hi thanks Sam

Unfortunately, same results in safe-mode - in response to a notification of pending users, there still is one missing from the queue to be reviewed even when I visit in discourse safe-mode with all three site customization items disabled.

What does this suggest?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2 november 2020 om 05:44 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/6 "2020-11-02T05:44:05Z")

</div>

Possibly that we need a review queue expert to have a look at this topic. I will flag this and someone will get back to you in the next few days.

Exact steps to reproduce the issue would a incredibly helpful.

---

<div class="post-metadata">

### Author: ![Paul\_King](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paul_king/32/165426_2.png) [@Paul\_King](https://meta.discourse.org/u/Paul_King)
#### Post date: [2 november 2020 om 06:04 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/8 "2020-11-02T06:04:53Z")

</div>

Thanks Sam.  
Very hard to identify exact steps - I am not sure what I have done that might be unusual, and I can not pin the onset of the issue to any specific event.

In my mind the main contenders are either a Discourse update, or an update to the multi-select plugin by @j.jaffeux on March 14 to ‘make values parsing more resilient’.

The problem is new signups are so intermittent that weeks can go by without one, so cause and effect can be very far apart in time.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2 november 2020 om 06:05 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/9 "2020-11-02T06:05:37Z")

</div>

Can you make the problem happen yourself by using chrome incognito and making fake accounts?

---

<div class="post-metadata">

### Author: ![Paul\_King](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paul_king/32/165426_2.png) [@Paul\_King](https://meta.discourse.org/u/Paul_King)
#### Post date: [2 november 2020 om 06:08 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/10 "2020-11-02T06:08:36Z")

</div>

I think I need to nominate a working email address in order for an application to even reach the queue?

I don’t have any email addresses that I have not already used for testing purposes - all already have accounts

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2 november 2020 om 06:10 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/11 "2020-11-02T06:10:08Z")

</div>

If you have gmail you can use + addressing … `jane+something@gmail.com` goes to `jane@gmail.com`

---

<div class="post-metadata">

### Author: ![Paul\_King](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paul_king/32/165426_2.png) [@Paul\_King](https://meta.discourse.org/u/Paul_King)
#### Post date: [2 november 2020 om 06:28 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/12 "2020-11-02T06:28:22Z")

</div>

OK, that was interesting - I attempted to use my Gmail account as above, but even while going to my Gmail webpage in another browser window and waiting for the Discourse generated verification email to turn up there, I was notified via my normal administrator email address about a new sign up to review.(and queue was empty as before). I had mistyped the address so never received the email to my Gmail account, so never verified.

So unless this is a coincidence, perhaps administrator notifications are jumping the gun? Though that would not explain why EVERY notification involves exactly one missing person in the queue - presumably there will not always be a failure to verify email address by one applicant but not the rest.

\*\* Edit

Subsequently, I corrected my Gmail address in that incognito signup window and resent the verification email - which then turned up at my Gmail browser window. I verified this using the verification url in another incognito window successfully. No subsequent notification was sent to my administrator email address, so I can only assume the first notification was indeed associated with this new sign up attempt.

Using yet another browser window, I visited the site again using safe-mode, signed in as administrator and saw the same queue still with one person to review - but this time my new test account was visible and could be approved.

Does any of this shed light on the issue?

---

<div class="post-metadata">

### Author: ![Paul\_King](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paul_king/32/165426_2.png) [@Paul\_King](https://meta.discourse.org/u/Paul_King)
#### Post date: [2 november 2020 om 08:21 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/13 "2020-11-02T08:21:25Z")

</div>

To follow up - I tried again and made a new fake account via incognito window (with correct address first time) - this attempt worked as expected, and responding to the emailed administrator notification via ordinary browser window I saw there was the new user visible in queue.

I repeated with new signup via standard window, and responding to notification via standard window (no incognito or [safe mode](https://meta.discourse.org/t/53504?silent=true) at any point) - and again all worked as it should - so the issue (or perhaps two issues - the notification to administrator even before email address verification by applicant, and the non appearance of the incomplete or completed application in the queue) was confined to the first attempt.

Again, not sure if this adds much clarity - but maybe once a first signup has been botched by the system (generating a phantom notification), subsequent signups then work ok? Maybe reverting to failure mode after enough time with no further signup activity has passed?

---

<div class="post-metadata">

### Author: ![Roman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roman/32/157504_2.png) [@Roman](https://meta.discourse.org/u/Roman)
#### Post date: [2 november 2020 om 10:49 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/14 "2020-11-02T10:49:03Z")

</div>

Hi @Paul_King

I suspect a migration I added around the same time as the commit you mentioned caused this issue, making some unapproved users look like they’re in the review queue and causing weird notifications.

Can you run this query on the [data explorer](https://meta.discourse.org/t/32566?silent=true) to confirm that this is the case?

```SQL
SELECT COUNT(*)
FROM users
INNER JOIN reviewables r ON r.target_id = users.id
WHERE r.type = 'User' AND r.status = 1 AND users.approved = FALSE

```

---

<div class="post-metadata">

### Author: ![Paul\_King](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paul_king/32/165426_2.png) [@Paul\_King](https://meta.discourse.org/u/Paul_King)
#### Post date: [2 november 2020 om 11:28 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/16 "2020-11-02T11:28:18Z")

</div>

Hi Roman.

I just ran it, and assuming I did it properly (see screenshot), the count was zero

 ![image](https://global.discourse-cdn.com/meta/original/3X/d/3/d3a53f3fcec6485e229aabf0270e24545116e68a.jpeg)

However my Discourse installation is currently also showing no users waiting.  
I have just now created another fake account, and had the addressed verified, but as yet no notification at all has been sent to my administrator email account. Logging back in to my site as administrator, I re-ran the query, and count was again zero, but this time Discourse otherwise now reports (correctly) that there is a user awaiting review

 ![image](https://global.discourse-cdn.com/meta/original/3X/3/0/3045281355ece72690e59bad23af160de504056e.png)

Normally users to review notification emails to my administrator address are pretty much immediate, so I am moderately certain this one never got sent. Now almost the opposite problem!

\*EDIT - I just now received a notification that TWO users were awaiting review (after an uncharacteristic delay). Still the small red icon by the hamburger menu showed the numeral ‘1’ , and clicking to review the queue showed only my own single fake user sign up from above - which I approved, and Discourse indicated no more users to review

After this I ran the query again - and count was zero.

---

<div class="post-metadata">

### Author: ![Roman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roman/32/157504_2.png) [@Roman](https://meta.discourse.org/u/Roman)
#### Post date: [2 november 2020 om 13:51 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/17 "2020-11-02T13:51:45Z")

</div>

Sorry, I realized that the WHERE clause is wrong. It should be `r.type = 'ReviewableUser'` instead of `User`.

Can you run this one instead?

```SQL
SELECT COUNT(*)
FROM users
INNER JOIN reviewables r ON r.target_id = users.id
WHERE r.type = 'ReviewableUser' AND r.status = 1 AND users.approved = FALSE

```

---

<div class="post-metadata">

### Author: ![Paul\_King](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paul_king/32/165426_2.png) [@Paul\_King](https://meta.discourse.org/u/Paul_King)
#### Post date: [2 november 2020 om 14:05 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/18 "2020-11-02T14:05:26Z")

</div>

Hi Roman  
I just received another phantom message, then reading your latest message ran the new query - same result - count=0

 ![image](https://global.discourse-cdn.com/meta/original/3X/0/0/0001f2305f592faf257ffaae5cfb60de850e945f.png)

---

<div class="post-metadata">

### Author: ![Roman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roman/32/157504_2.png) [@Roman](https://meta.discourse.org/u/Roman)
#### Post date: [2 november 2020 om 16:48 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/19 "2020-11-02T16:48:51Z")

</div>

It has to be something else then. I’ll investigate.

---

<div class="post-metadata">

### Author: ![Roman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roman/32/157504_2.png) [@Roman](https://meta.discourse.org/u/Roman)
#### Post date: [9 november 2020 om 21:45 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/21 "2020-11-09T21:45:41Z")

</div>

Hey @Paul_King,

Would you mind checking if your site has any unapproved users without an associated reviewable object? I’ve been trying to reproduce this bug without luck so far.

Here’s a query to do so:

```SQL
SELECT COUNT(*) 
FROM users u
LEFT JOIN reviewables r ON r.target_id = u.id AND r.type = 'ReviewableUser'
WHERE approved = false AND r.id IS NULL

```

also, try:

```SQL
SELECT COUNT(*) FROM users WHERE approved = false AND active = true

```

---

<div class="post-metadata">

### Author: ![Paul\_King](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/paul_king/32/165426_2.png) [@Paul\_King](https://meta.discourse.org/u/Paul_King)
#### Post date: [9 november 2020 om 22:16 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/22 "2020-11-09T22:16:03Z")

</div>

Hi thanks Roman

Here is result of first query:

 ![image](https://global.discourse-cdn.com/meta/original/3X/e/7/e7447145bc722a62c498fa7bd7f574cd692b7300.png)

Not sure if relevant, but there are a lot of posts that were imported from a defunct yahoo group that is the precursor to current forum - merged in for continuity and searchability reasons. The creators of those old posts (dating back to early 2000’s) often won’t have accounts on the current forum.

The results of second query below:

 ![image](https://global.discourse-cdn.com/meta/original/3X/e/0/e0bc884888c49298ef0be54cc0acefc36b6955cd.png)

This was very interesting - how can someone have an unapproved account but be active? Unless it is me as the administrator? How can I tweak query to identify that user?

---

<div class="post-metadata">

### Author: ![Roman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/roman/32/157504_2.png) [@Roman](https://meta.discourse.org/u/Roman)
#### Post date: [10 november 2020 om 00:04 UTC](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631/23 "2020-11-10T00:04:10Z")

</div>

> [@Paul\_King](#):
>
> how can someone have an unapproved account but be active?

That just means it’s waiting for approval.

> [@Paul\_King](#):
>
> How can I tweak query to identify that user?

`SELECT * FROM users WHERE approved = false AND active = true`

The username will be a link to the user profile. After you identify it, can you share the `created_at` date? I’d like to know if we change something around that date.

[Next page](https://meta.discourse.org/t/phantom-signups-two-users-with-the-same-account-after-migration/168631.md?page=2)
