Should personal information, email, be removed from the magic link in Email provider #4291
Replies: 1 comment 1 reply
-
We just had a security audit done our our software, and this exact issue was raised:
And both @balazsorban44, sorry for pinging you directly, I'm not sure if this should go through the vulnerability reporting or not, but I'd love to hear your opinion on this. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Would a (longer and shorter expiry) token be enough to identify the magic link?
Leaving a breadcrumb of personal information via URLs don't seem like a great default for a auth package. Was this ever discussed? Was there a concern with lack of rate-limiting or anything else that stopped from having a single or combination of tokens?
I couldn't find any issues/discussions, so tarting one here.
Beta Was this translation helpful? Give feedback.
All reactions