Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve email verification #1

Open
husseinalhammad opened this issue Jun 27, 2020 · 0 comments
Open

Improve email verification #1

husseinalhammad opened this issue Jun 27, 2020 · 0 comments
Labels
enhancement New feature or request help wanted Extra attention is needed

Comments

@husseinalhammad
Copy link
Member

The email verification is under-engineered and not foolproof.

The verification token sent via email is really just a base64 encoded string. While it does not contain sensitive information, it is possible for an existing member to reverse engineer it when they change their email address and verify their new email address without actually having access to the new email address.

@husseinalhammad husseinalhammad added enhancement New feature or request help wanted Extra attention is needed labels Jun 27, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request help wanted Extra attention is needed
Projects
None yet
Development

No branches or pull requests

1 participant