You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I don't see any use in allow users to forward their magic links and exposing this larger security hole.
It would be nice if the library stored a cookie on the client when they request a magic link and when logging it, it can check to ensure the cookie is there, if not, the login attempt fails.
The text was updated successfully, but these errors were encountered:
I'm not completely sure what you're asking. Maybe you're referring to this?
When hitting the login view, the link passed with the next query parameter is saved in a cookie. The redirect only happens if the target is a safe URL:
I don't see any use in allow users to forward their magic links and exposing this larger security hole.
It would be nice if the library stored a cookie on the client when they request a magic link and when logging it, it can check to ensure the cookie is there, if not, the login attempt fails.
The text was updated successfully, but these errors were encountered: