# User required actions not sending the specific email when set through Admin UI or custom federation provider

**URL:** <https://forum.keycloak.org/t/user-required-actions-not-sending-the-specific-email-when-set-through-admin-ui-or-custom-federation-provider/9773>\
**Category:** Miscellanaeous\
**Tags:** admin-console, user-federation\
**Created:** [June 25, 2021, 7:30am UTC](https://forum.keycloak.org/t/user-required-actions-not-sending-the-specific-email-when-set-through-admin-ui-or-custom-federation-provider/9773 "2021-06-25T07:30:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ronny](https://avatars.discourse-cdn.com/v4/letter/r/94ad74/32.png) [@ronny](https://forum.keycloak.org/u/ronny)\
**Post date:** [June 25, 2021, 7:30am UTC](https://forum.keycloak.org/t/user-required-actions-not-sending-the-specific-email-when-set-through-admin-ui-or-custom-federation-provider/9773/1 "2021-06-25T07:30:23Z")

</div>

Hey there,  
I have implemented a custom user federation provider to migrate users from our “legacy” system to Keycloak. This works without any problems.

The problem or struggle occurs when I am setting the required actions to a specific user:

```auto
 getRequiredActions(legacyUserDetails)
                .forEach(keycloakUser::addRequiredAction);

```

```auto
 private Stream<UserModel.RequiredAction> getRequiredActions(LegacyUserDetails legacyUserDetails) {
        return requiredActionMap.entrySet()
                .stream()
                .filter(predicateSupplierEntry -> predicateSupplierEntry.getKey().test(legacyUserDetails))
                .map(it -> it.getValue().get());
    }

```

The required actions are set as expected to the specific user. They are also visible in the Keycloak admin console UI for the specific user, **but** Keycloak is **not sending an E-Mail** for example for the `VERIFY_EMAIL` required action.

I have also tried to remove and read the required action in the Keycloak admin console UI, but the result stays the same: No E-Mail is sent to the specific user. This is also the case for the `UPDATE_PASSWORD` action.

So, how to trigger the E-Mail sent for the required actions? If I migrate a user which E-Mail is not verified I need to sent a specific E-Mail.  
The SMTP Server is configured, and `Test Connection` Mails are sent and received successfully.

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [June 25, 2021, 6:17pm UTC](https://forum.keycloak.org/t/user-required-actions-not-sending-the-specific-email-when-set-through-admin-ui-or-custom-federation-provider/9773/2 "2021-06-25T18:17:21Z")

</div>

The emails are not triggered by the addition of a required action. You need to call the `execute-actions-email` endpoint in the Admin API ([Keycloak Admin REST API](https://www.keycloak.org/docs-api/14.0/rest-api/index.html#_executeactionsemail)) for it to both add the required actions and send an email.

---

<div class="post-metadata">

**Author:** ![ronny](https://avatars.discourse-cdn.com/v4/letter/r/94ad74/32.png) [@ronny](https://forum.keycloak.org/u/ronny)\
**Post date:** [June 27, 2021, 2:10pm UTC](https://forum.keycloak.org/t/user-required-actions-not-sending-the-specific-email-when-set-through-admin-ui-or-custom-federation-provider/9773/3 "2021-06-27T14:10:21Z")

</div>

That makes not much sense to me.  
I am inside a custom SPI within keycloak where I migrate the legacy users to keycloak and explicitly set the required actions.

If I understood you correctly, I need to use the Keycloak REST API **inside** the Keycloak context (as I am running a custom SPI) to invoke the Mail sending?

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [June 27, 2021, 3:07pm UTC](https://forum.keycloak.org/t/user-required-actions-not-sending-the-specific-email-when-set-through-admin-ui-or-custom-federation-provider/9773/4 "2021-06-27T15:07:25Z")

</div>

Yes, it is a bit confusing. That’s where the code is that will set a required action AND send the email to the user. I don’t know of a convenient place elsewhere it exists in the code that’s easy to call from an SPI. You can either:

1. Load the provider from your SPI using the `KeycloakSession getProvider(...)` method to get and execute that method on the `UserResource`.
2. Duplicate the code from the `UserResource executeActionsEmail(...)` method in your own SPI to set the required actions and send the email.
3. Call that method in the Admin API from your SPI. If your SPI is an authenticated REST resource, you can use the token you got there. If not, you could use a service account to authenticate and call the API.

---

<div class="post-metadata">

**Author:** ![ronny](https://avatars.discourse-cdn.com/v4/letter/r/94ad74/32.png) [@ronny](https://forum.keycloak.org/u/ronny)\
**Post date:** [June 28, 2021, 3:08pm UTC](https://forum.keycloak.org/t/user-required-actions-not-sending-the-specific-email-when-set-through-admin-ui-or-custom-federation-provider/9773/5 "2021-06-28T15:08:00Z")

</div>

So what I have no tried, even if it is totally ugly:

```auto
 public class LegacyProvider implements UserStorageProvider,
         UserLookupProvider,
         CredentialInputUpdater,
       CredentialInputValidator {
....
 Keycloak instance = Keycloak.getInstance(
                "http://localhost:8080/auth/",
                "master",
                "admin", "myMasterPassword",
                "admin-cli");

....
instance.realm(realm.getName()).users().get(user.getId()).executeActionsEmail(user.getRequiredActionsStream().collect(Collectors.toList()));

```

But I am missing something. I always get

```auto

15:05:08,247 ERROR [org.keycloak.services.error.KeycloakErrorHandler] (default task-8) Uncaught server error: javax.ws.rs.ProcessingException: RESTEASY004655: Unable to invoke request: org.apache.http.conn.HttpHostConnectException: Connect to localhost:8080 [localhost/127.0.0.1] failed: Connection refused (Connection refused)

```

---

<div class="post-metadata">

**Author:** ![prifulnath](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/prifulnath/32/10323_2.png) [@prifulnath](https://forum.keycloak.org/u/prifulnath)\
**Post date:** [April 30, 2024, 11:53am UTC](https://forum.keycloak.org/t/user-required-actions-not-sending-the-specific-email-when-set-through-admin-ui-or-custom-federation-provider/9773/6 "2024-04-30T11:53:12Z")

</div>

Hey @ronny got any solution for this?
