4 ms·
One problem that I noticed is that not all OAuth providers give you the users emails as part of authentication data. Twitter and LinkedIn for instance dont, whe
by codenerdz 15y ago
One problem that I noticed is that not all OAuth providers give you the users emails as part of authentication data. Twitter and LinkedIn for instance dont, whereas Facebook does.
How do you handle that?
- bane 15y agoThat's a good question. We're planning on adding support for all three of those in the near-ish future. Very likely we're going to have to engineer an additional sign-in step for Twitter and LinkedIn that we don't need from Oauth providers that do provide the info: 1) Click login 2) choose twitter or linkedin 3) if the account is new, ask for name and email address 4) send out confirmation email with account activation link 5) user clicks activation link in the email 6) done The reason for the activation email is that we really really need to confirm the address for our service to work correctly and to protect ourselves from spam. Otherwise we'd just accept what they enter. For Twitter, we may decide to provide a slightly modified version of our service for scheduled tweets rather than scheduled email, but that'll be a ways off. In that case, if I remember correctly, we should get all of the relevant info from Oauth anyways.