<AddUser>
After a form submits successfully, registers a new user in DNN with the supplied profile information. Optionally adds the user to one or more security roles via RoleNames, and sets custom profile properties via <Property> child tags.
Validate user input — and lock the form down
Public registration forms are a target for abuse. Always validate the form's inputs and protect the form so only the audience you intend can submit it.
Verified registration sites: do not list auto-assigned roles in RoleNames
If your site's registration type is Verified (Site Settings → User Accounts → Registration Settings), DNN places a new account in the Unverified Users role only and waits for the person to click the link in the verification email. Only then does DNN add them to the site's auto-assigned roles, such as Registered Users.
RoleNames does not wait. It adds the new user to every role you list the moment the account is created, before the email is verified. Listing Registered Users (or any other role with Auto Assignment turned on) hands an unverified account the access that verification is meant to protect, and anyone can register with a throwaway email address.
Leave auto-assigned roles out of RoleNames. DNN adds them itself once the user is verified. The same timing applies to any role you grant at signup, including roles granted afterward with <AddToRoles UserId="[[__UserId]]">, so on a Verified site treat any role in RoleNames as taking effect immediately.
Passing the new UserID downstream
On success, XMP adds a __UserId token (two underscores + UserId) to the form data, so later action tags (e.g. <AddToRoles>, <Redirect>) can reference the new user by ID. Available since v4.1.
Action timing
Action tags only run when the form submits successfully. They evaluate their tokens at that point — not when the form loads — so [[FieldName]] tokens read user input. Actions run in document order; an action that fails throws away every action listed below it.
Example
<AddForm>
<AddUser RoleNames="Role1,Editors" Email="[[Email]]"
FirstName="[[FName]]" LastName="[[LName]]"
Username="[[Username]]" Password="[[Password]]" />
<table>
<tr>
<td>
<Label For="txtFirstName" Text="First Name" />
<TextBox Id="txtFirstName" DataField="FName" DataType="String" />
<Validate Type="Required" Target="txtFirstName" Text="**" Message="First Name is required." />
</td>
</tr>
<tr>
<td>
<Label For="txtLastName" Text="Last Name" />
<TextBox Id="txtLastName" DataField="LName" DataType="String" />
<Validate Type="Required" Target="txtLastName" Text="**" Message="Last Name is required." />
</td>
</tr>
<tr>
<td>
<Label For="txtEmail" Text="Email" />
<TextBox Id="txtEmail" DataField="Email" DataType="String" />
<Validate Type="Required" Target="txtEmail" Text="**" Message="An email address is required." />
<Validate Type="Email" Target="txtEmail" Text="**" Message="Please enter a valid email address." />
</td>
</tr>
<tr>
<td>
<Label For="txtUsername" Text="Username" />
<TextBox Id="txtUsername" DataField="Username" DataType="String" />
<Validate Type="Required" Target="txtUsername" Text="**" Message="Please enter a Username." />
</td>
</tr>
<tr>
<td>
<Label For="txtPassword" Text="Password" />
<Password Id="txtPassword" DataField="Password" DataType="String" />
<Validate Type="Required" Target="txtPassword" Text="**" Message="A Password is required." />
</td>
</tr>
<tr>
<td colspan="2"><AddButton Text="Add" /> <CancelButton Text="Cancel" /></td>
</tr>
<tr>
<td colspan="2"><ValidationSummary DisplayMode="BulletList" HeaderText="Errors:" CssClass="NormalRed" /></td>
</tr>
</table>
</AddForm>Properties
Required
| Property | Values | Default | Description |
|---|---|---|---|
| Username * | string | Unique username for the new account | |
| Email * | The new user's email address | ||
| FirstName * | string | The new user's first name | |
| LastName * | string | The new user's last name | |
| Password * | string | Password for the new account |
User profile
| Property | Values | Default | Description |
|---|---|---|---|
| DisplayName | string | (FirstName + LastName) | Name displayed throughout DNN. If omitted, defaults to "FirstName LastName" |
| Approved | True False | False | When True, the user is auto-approved and can log in immediately |
| UpdatePasswordOnNextLogin | True False | False | When True, the user is prompted to change their password at first login |
| Country | string | Country (mapped to DNN profile) | |
| Region | string | Region/state (mapped to DNN profile) | |
| City | string | City (mapped to DNN profile) | |
| PostalCode | string | Zip / postal code (mapped to DNN profile) | |
| Street | string | Street address (mapped to DNN profile) | |
| Unit | string | Unit / apartment (mapped to DNN profile) | |
| Telephone | string | Telephone (mapped to DNN profile) | |
| RoleNames | comma-list | One or more DNN role names. The new user is added to each | |
| SendVerificationEmail | True False | False | (Ignored as of v4.6.) DNN now sends the verification email automatically based on the portal's registration mode |
Error messages
When DNN rejects the user creation, <AddUser> throws an action error using one of these messages. Override them to localize or customize the wording.
| Property | Default |
|---|---|
| ErrMsgDuplicateEmail | "The email address already exists" |
| ErrMsgInvalidEmail | "The supplied email is invalid" |
| ErrMsgInvalidPassword | "The supplied password is invalid" |
| ErrMsgInvalidUsername | "The supplied username is invalid" |
| ErrMsgDuplicateUser | "The user is already registered" |
| ErrMsgDuplicateUsername | "The username already exists" |
* Required property
Child Tags
| Tag | Required | Description |
|---|---|---|
<Property> | optional | Sets a custom DNN profile property on the new user |
<Property>
Sets a single custom profile property. Use one <Property> tag per property to set.
| Attribute | Values | Default | Description |
|---|---|---|---|
| Name * | string | Profile property name (must already exist in DNN) | |
| Value | string | token | Value to assign |
<AddUser Email="[[Email]]" Username="[[Username]]" Password="[[Password]]"
FirstName="[[FName]]" LastName="[[LName]]">
<Property Name="Biography" Value="[[Bio]]" />
<Property Name="Twitter" Value="[[TwitterHandle]]" />
</AddUser>Property Details
DisplayName: The name DNN shows in places like the user menu and post bylines. If omitted (or empty),
<AddUser>builds it fromFirstNameandLastName.RoleNames: A comma-delimited list of DNN security role names. After the user is created,
<AddUser>adds them to each named role immediately, regardless of whether the account has been approved or verified. Do not list roles DNN assigns automatically (Registered Users, Subscribers, or any role with Auto Assignment turned on): DNN adds those itself, and on a Verified registration site it does so only after the user verifies their email. See the warning above. For more control (start/end dates, custom delimiter, conditional adds), use a separate<AddToRoles>action with the[[__UserId]]token.