3 ms·
That “Magic Link”/passwordless auth flow was pretty slick in that the verification link does not authenticate the browser that it opens from your email, but rat
by spennant 5y ago
That “Magic Link”/passwordless auth flow was pretty slick in that the verification link does not authenticate the browser that it opens from your email, but rather the browser that your email address was originally entered in gets refreshed and logged-in when the link is clicked.
Is there a trusted Open Source package that does this?
- callahad 5y agoHubs itself is open-source; you should be able to find whatever library it's using if you dig in the relevant repos. > the verification link does not authenticate the browser that it opens from your email, but rather the browser that your email address was originally entered in That is much slicker (and necessary in the case of Hubs, where you may not be able to access your email from within a VR environment), but it also carries risk: Naïve implementations would open you up to attack if you accidentally clicked the link on an email sent in response to someone else entering your email address in the app.
- spennant 5y agoI dug… it doesn't seem to be a lib. And yeah… that attack vector is ripe for abuse.