5 ms·
Hmm, yea I made it so that each password token can only be used once in case someone gets a hold of your email. I can see how that can be annoying. I'll work on
by ny2244111 12y ago
Hmm, yea I made it so that each password token can only be used once in case someone gets a hold of your email. I can see how that can be annoying. I'll work on a solution to that. Thanks for the feedback.
- JosephRedfern 12y agoYeah, that makes sense - the problem was the resulting lock-out.
- shanecleveland 12y agoIf someone gets a hold of your email, they could easily request another login token anyway. I think it's fine if it doesn't expire.
- ny2244111 12y agoNow I remember why I made it expire and/or only usable once. Consider public places or caching. Since the temporary authentication token is exposed in the URL there is a risk that someone else can reuse it. Whereas if it's a one time temporary token then you should be OK. I think I need to be more explicit in that this is a one time token. The whole passwordless thing is new so there are some pain points.