2 ms·
Correct. The only thing I’d also like to mention is security. 1. If there are XSS vulnerabilities on the website, an attacker could be able to use iframes (at
by aruseni 13y ago
Correct. The only thing I’d also like to mention is security.
1. If there are XSS vulnerabilities on the website, an attacker could be able to use iframes (at least if you haven’t set X-Frame-Options to DENY) or XMLHttpRequest to retrieve an authentication QR code and use it to log into the user’s account.
2. Even without any XSS, it is possible that someone who has access to the user’s session (for example, if the user is still logged in on the website, but is away from the computer) could scan the QR code and, therefore, log into the user’s account.
Possible solutions include sending the QR code by email (actually, some users are always logged into their email accounts as well, so this might be meaningless) and prompting the user for their password before displaying the QR code (it is still much easier to type the password on a desktop/laptop computer’s keyboard rather than type the site address + login or email + password on a mobile device’s virtual keyboard).