3 ms·
> Also the page that initiated it should periodically refresh itself to see if the session was validated somewhere else. I guess the link must be disabled / in
by mffap 4y ago
> Also the page that initiated it should periodically refresh itself to see if the session was validated somewhere else.
I guess the link must be disabled / invalidated after first use and your auth server and client obviously must verify if a given link is still valid.
- mojuba 4y agoOf course the link should be invalidated, but that doesn't protect from a situation where an attacker initiates a login, then the user receives an email and clicks. The chances are slim but some people might get confused and click without much thinking - and voila, the attacker has a valid session.
- pritambaral 4y agoSimply opening a Magic Link doesn't have to authenticate the initiating login. The user can be asked to interact with the page, being shown the source of the link (time, browser, device, IP/Region, etc.), to authenticate the login. This adds a little bit of friction to legitimate cases, but then again having to open your email and find a link and click it is already plenty of friction that this additional step can be considered a negligible addition to that.