Should personal information, email, be removed from the magic link in Email provider #4291
Replies: 1 comment 1 reply
-
We just had a security audit done our our software, and this exact issue was raised:
And both @balazsorban44, sorry for pinging you directly, I'm not sure if this should go through the vulnerability reporting or not, but I'd love to hear your opinion on this. |
Beta Was this translation helpful? Give feedback.
-
Would a (longer and shorter expiry) token be enough to identify the magic link?
Leaving a breadcrumb of personal information via URLs don't seem like a great default for a auth package. Was this ever discussed? Was there a concern with lack of rate-limiting or anything else that stopped from having a single or combination of tokens?
I couldn't find any issues/discussions, so tarting one here.
Beta Was this translation helpful? Give feedback.
All reactions