3 ms·
My suggestion was simply that they add a has to go with the email parameter (since they generated the URL), such that you can't just check against an email (and
by TomAnthony 9y ago
My suggestion was simply that they add a has to go with the email parameter (since they generated the URL), such that you can't just check against an email (and you can't generate the hash).
The scope of the issue is limited, but the fix also does not seem that hard. However, I appreciate it is easy to throw out such an idea, and the reality of implementing it is probably a bit harder. :)