#8601 email auth verification by link

unreleased
closed
None
General
nobody
2026-05-01
2026-04-22
No

With a link we can have a longer token for more security (still type-able if needed). And the link will defeat some MITM phishing attacks, forcing you to the right site.

We can apply this to 2FA accounts too (currently being skipped) so they get the MITM protections too

Downside is if you don't have email access on the same computer you're logging in to :(

Discussion

  • Dave Brondsema

    Dave Brondsema - 2026-04-22
    • status: in-progress --> review
     
  • Dave Brondsema

    Dave Brondsema - 2026-04-22

    db/8601

     
  • Dillon Walls - 2026-05-01
    • status: review --> closed
     
  • Dillon Walls - 2026-05-01

    looks good, merged.

    There are a few more improvements we could make, but this is a considerable step in the right direction.

     

Log in to post a comment.