3 ms·
This is actually the same method we use for logins, when the cookie is absent or expired, at a forum I'm currently running. They get sent a unique login token t
by eksith 13y ago
This is actually the same method we use for logins, when the cookie is absent or expired, at a forum I'm currently running. They get sent a unique login token that expires in a few minutes (or is force expired if they request a resend of the login token) and get presented a CAPTCHA after following the link if they've already tried a few times.
Login email delay increases exponentially with each request.