3 ms·
My use of authorization was a bit vague.. what I meant is that with your scheme, you implicitly assume I want a particular application to be authenticated. Thi
by linuxdude314 3y ago
My use of authorization was a bit vague.. what I meant is that with your scheme, you implicitly assume I want a particular application to be authenticated.
This leaves the user vulnerable to someone else launching accounts on providers they don’t use, that point to your verification record.
It’s much more secure to add a DNS record for each system (maybe even each instance/user) as you are explicitly authorizing access to that application via your domain.