3 ms·
I wish OAuth said something about what to do when someone signs up with email/pass and then logs in using the same email via OAuth later. I get that this is out
by block_dagger 2y ago
I wish OAuth said something about what to do when someone signs up with email/pass and then logs in using the same email via OAuth later. I get that this is outside the scope of the spec but it would be helpful if there were a standard around this. My opinion: merge the accounts and allow the user to login either way.
- solatic 2y agoIdeally, you have a flow where you ask the user to input their password to confirm ownership, then merge. Otherwise, you're allowing the OAuth provider to back-door into established accounts.
- block_dagger 2y agoGood call. I had not considered the OAuth provider acting nefariously.