4 ms·
Consider a different approach to mitigate automated URL fetching interference (this can apply to both email ownership verifications and password resets). Make
by mtwittman 5y ago
Consider a different approach to mitigate automated URL fetching interference (this can apply to both email ownership verifications and password resets).
Make the emailed verification/reset link (GET request) idempotent (1 and >1 request has the same effect).
Have the link just present an interface for the user to take the next step. In the next step make a POST request that actually commences your verification/reset process.
In all likelihood you'll want expiry logic (let's say it's 30 minutes) - if you store the token with a created_at timestamp on the server you can have your verification/reset process check that now < (created_at + 30 minutes)
If expired, provide a UI for the user to request a fresh verification/reset email.