4 ms·
The HTTP GET method is idempotent: it should behave the same way on multiple accesses. A single use link, e.g. for resetting a password or confirming a subscri
by oever 4y ago
The HTTP GET method is idempotent: it should behave the same way on multiple accesses.
A single use link, e.g. for resetting a password or confirming a subscription, will usually show a webpage with a form that does a POST. Once that POST has been performed, the single use link is used up.
Single use links will mostly have a one-time secret that should not be leaked. Mails that contain such links or any sensitive information should be encrypted.
- weberer 4y agoHow do you send mail to an Outlook user and encrypt it so Microsoft can't snoop on it?
- deleted 4y ago[deleted]
- diegoperini 4y agoYou re-ask the password on the visited page before presenting the form responsible for the one time POST call.
- jeroenhd 4y agoIf your goal is to prevent third party software like spam filters and malware engines from triggering actions, you must require a second step that will send a POST/PUT/anything-that-isn't-idempotent request. You can copy the authentication code into a form field and do the entire thing without Javascript if you want to, but a second step is necessary. If your goal is to hide your secrets from Microsoft, then send the email encrypted or don't send it to Microsoft's servers at all. This is practically impossible, it at least impractical in most cases. You can't control the hosting provider and software of your customers.