brave / ads-ui

Self-service ads UI
Mozilla Public License 2.0
23 stars 11 forks source link

feat(login): obtain user consent when verifying magic link #1302

Closed IanKrieger closed 1 month ago

IanKrieger commented 1 month ago

Introduce better Anti-CSRF protections by prompting the user to make sure that every login request is an intentional request.


https://github.com/user-attachments/assets/e45b9f94-7246-4601-b63a-bc8a859f85f0

github-actions[bot] commented 1 month ago

The security team is monitoring all repositories for certain keywords. This PR includes the word(s) "login" and so security team members have been added as reviewers to take a look.
No need to request a full security review at this stage, the security team will take a look shortly and either clear the label or request more information/changes.
Notifications have already been sent, but if this is blocking your merge feel free to reach out directly to the security team on Slack so that we can expedite this check.