3 ms·
Sure! Basically, reuse a lot of signing functions that you might find in a library (IE: Django's https://docs.djangoproject.com/en/dev/topics/signing/ https://
by bryanh 13y ago
Sure!
Basically, reuse a lot of signing functions that you might find in a library (IE: Django's https://docs.djangoproject.com/en/dev/topics/signing/ https://docs.djangoproject.com/en/dev/topics/signing/), don't roll your own. Then, keep track of last login IP address and block auto-logins when they mismatch. Then, set a max age for the login links to work (for example, 24 hours). There are a few other things we do as well, but those are the major ones.
Those three combined are fairly secure.
- mmahemoff 13y agoThanks. You said "last login IP". If it's a single IP, I guess you're talking about transactional mails the user has triggered. If it was marketing mails, you'd surely want to compare against a list of recent IPs, not just the very last, wouldn't you?