Skip to main content

Uni-Verein 1.8.0 – Self-Enrollment Ready for Permanent Use πŸ“βœ…

Β· 3 min read
RenΓ© Herrmann
Senior developer

Published on September 20, 2026

Uni-Verein 1.8.0 makes self-enrollment originally built for short-term use such as a trade fair booth - ready for permanent operation: registrations now only create a member after the email address is confirmed and a logged-in person has reviewed them, instead of immediately. On top of that comes a new opt-in notification for new registrations and a security fix for already-paid receipts.

Highlights​

  • πŸ“ Hardened self-enrollment: Email confirmation (48h) plus a review queue instead of creating the member directly
  • πŸ”” Opt-in notification: Any logged-in user can get an email whenever a new registration comes in
  • πŸ”’ Receipt fix: A regular user can no longer delete a receipt that's already been marked as paid

New Features​

  • πŸ“ Self-enrollment: The public form no longer creates a member directly, it first requires confirming the submitted email address via a link valid for 48 hours. Only then does the registration land in the "Pending members" tab of member management, visible to every logged-in role, where it can be approved or rejected
  • ✍️ Motivation instead of category: Applicants instead provide a short motivation plus required IBAN and BIC, a member category is only assigned by the reviewer when approving
  • πŸ›‘οΈ Hardened for everyday use: Per-IP rate limiting, stricter email validation, a requirement that mail settings are configured before self-enrollment can be enabled, and a mobile-friendly view for the review queue
  • πŸ”” New-enrollment notification: Any logged-in user, regardless of role, can opt in via a new toggle in the notification settings to receive an email for every newly confirmed registration, off by default

Fixes​

  • πŸ”’ Deleting a paid receipt: A regular user could still delete their own receipt even after an Admin or Finance Manager had marked it as paid, because the delete check only looked at receipt ownership, not the paid status. Deleting a paid receipt as a regular user now returns an error, and the delete button is hidden for it. Admins and Finance Managers can still delete paid receipts

Why These Updates Matter​

The original self-enrollment feature was built for short-term use, such as quickly signing up new members at an event. Running it permanently on the club website needs more safeguards: email confirmation prevents registrations with incorrect or someone else's address, the review queue keeps the board in control of every new admission, and the opt-in notification means nobody has to manually check whether something new is waiting.

What's Next?​

Real-world feedback is, as always, very welcome via GitHub Issues. Check back here again soon!