#8601 email auth verification by link

unreleased
review
None
General
nobody
4 days ago
4 days ago
No

With a link we can have a longer token for more security (still type-able if needed). And the link will defeat some MITM phishing attacks, forcing you to the right site.

We can apply this to 2FA accounts too (currently being skipped) so they get the MITM protections too

Downside is if you don't have email access on the same computer you're logging in to :(

Related

Commit: [09208d]
Commit: [4cf8e1]
Commit: [7fd219]
Commit: [d18050]
Commit: [f8a696]
Commit: [fd3428]

Discussion

  • Dave Brondsema

    Dave Brondsema - 4 days ago
    • status: in-progress --> review
     
  • Dave Brondsema

    Dave Brondsema - 4 days ago

    db/8601

     

Log in to post a comment.