3 ms·
I just love it when they "scan" password reset links.
by usrn 4y ago
I just love it when they "scan" password reset links.
- noisem4ker 4y agoThe HTTP GET method is idempotent by specification. Visiting a webpage should not trigger password resets or any other actions by itself. If that's a problem then it's the site's fault for being defective.
- rsbadger 4y agoYou’re right that it was a bit of an oversight on my behalf, as the links were only generated after a verified human user action (signup) I had assumed the 1 time links to their email would be safe. But regardless of the link action, it shouldn’t be passing that data to Bingbot to crawl and (possibly) index in search engine results. Private email data should not be shared with search engine crawlers IMO.
- petercooper 4y agoSo how do you implement a "one click unsubscribe" link in an email? They're on GET requests. You could use JavaScript on the resulting page to then trigger the unsubscribe but bots are now running JavaScript as well.
- noisem4ker 4y agoYou show a webpage with an "Unsubscribe" button in it. The button triggers a POST request. There's also RFC 8058: https://datatracker.ietf.org/doc/html/rfc8058 https://datatracker.ietf.org/doc/html/rfc8058
- AtNightWeCode 4y agoThat should send one to a page with a confirmation button...