4 ms·
At the moment authorization relies on the secrecy of the unique address, yes. I wanted to keep it simple. As long as you don't share that address, which is clos
by SkyLinx 5y ago
At the moment authorization relies on the secrecy of the unique address, yes. I wanted to keep it simple. As long as you don't share that address, which is close to impossible to guess, you should be fine. Is there something else you would recommend I implement, that doesn't impact on usability? Thanks!
- throwawayboise 5y agoI'm not an expert here, but I suppose that only processing emails that have pass all the SPF/DKIM/DMARC checks would help. This may be something your email server already does, before your app ever sees the emails. Otherwise, requiring a digital signature doesn't seem like a huge usability hurdle to me, most email clients support this pretty routinely.
- ipaddr 5y agoThat would be such a big hurdle for the average user. The risk is low and the subject(blog) makes this a low target.
- SkyLinx 5y agoYeah I think it would be a little overkill. The unique email addresses are almost impossible to guess so you just need to make sure you don't share them with anyone.
- thepratt 5y agoJust thinking out loud here, what about having to attach a key as an attachment?
- SkyLinx 5y agoWhat kind of key? I am just afraid to make it "complicated" because now it's as simple as sending an email to some address. :)
- thepratt 5y agoYou would provide this file for them to download alongside where you show the email address; the file would be equivalent to an API key - should be a symmetric key. It's sort of just swapping out an Authorization header for a file with an expected checksum/contents. If the barrier is technical abilities, trying to set up public/private keys and/or signing the emails could hinder adoption.
- SkyLinx 5y agoI'll think about it. For me keeping things simple is a priority. What are the chances that a user might share the unique email address by mistake?
- MathCodeLove 5y agoOne more suggestion that would, IMO, be fairly simple. Tell the user to write in their subject line a {accessKey: 'someKey'}. The access key is given to them at the time of creation and can be regenerated as often, or rarely, as the user prefers. If they want update it weekly to provide an extra layer of security they can, or they could keep it the same forever with it just bein a handy backup in case they do link the random email. Just a thought.
- ithkuil 5y agoIs it easy to regenerate that address when I want to?
- SkyLinx 5y agoNot currently, but it would be a few minutes work to add that possibility. I'll take a note about it :)
- ihadfun 5y agoHow about having an option to “approve” the post. For example, after I email the post the system sends an email to my registered address with “publish” and “deny” buttons. One click and it’s done.
- SkyLinx 5y agoI'm taking a note. Shouldn't take too long to implement but I think this would be optional as some people could be happy with the just difficult to guess address. :)