4 ms·
The link is a "safe" GET request. The page loaded via the link should do an "unsafe" POST for the login, via javascript with a form button for fallback. https:
by snthd 2y ago
The link is a "safe" GET request.
The page loaded via the link should do an "unsafe" POST for the login, via javascript with a form button for fallback.
https://www.rfc-editor.org/rfc/rfc7231#section-4.2.1 https://www.rfc-editor.org/rfc/rfc7231#section-4.2.1
>The purpose of distinguishing between safe and unsafe methods is to allow automated retrieval processes (spiders) and cache performance optimization (pre-fetching) to work without fear of causing harm. In addition, it allows a user agent to apply appropriate constraints on the automated use of unsafe methods when processing potentially untrusted content.
Exactly the same for email unsubscribe links, or a one click "buy now" link.
- justinator 2y agoAutomatic link pre-fetchers know JavaScript too and will trigger your JavaScript to post. I've had to implement a system where if the link was minted x minutes ago, the JavaScript on the landing page is disabled. It's just another arms race. It shouldn't be this hard, but in email it seems everything is additionally harder to do.
- adastra22 2y agoWhy not just have a username & password. Why make everything so complicated? We just successfully got password managers deployed to most users, only to drop passwords entirely for a subpar system?
- cuu508 2y ago> We just successfully got password managers deployed to most users Source?
- adastra22 2y agoEvery desktop and mobile OS has a built-in password manager perfectly adequate for this use case, with encrypted sync and backup capabilities.
- justinator 2y agoOne example is an unsubscribe link. Legally, it would be no bueno to have it behind any sort of login. Another is just counting if a link from an email was clicked. I want friction to be as little as possible. That's done by having some sort of redirect, but you have to use a JavaScript initiated post to weed add false positives. That's already ridiculous, but because of automated link prefetchers, you still need to disable that and show a f'n button. And then I have to answer to clients that want to know why their clickthrough stats are down precipitously and I don't honestly have the wherewithall to explain the inner workers of every filter that snoops their email before they read it.
- apitman 2y agoIf you want to do this without JS just add a page with a "Click here to complete login" button that does the POST.