breach-tw / breach.tw

A service that can track data breaches like "Have I Been Pwned", but it is specific for Taiwan.
https://breach.tw
MIT License
158 stars 22 forks source link

Email Verification might be invalid #108

Open seadog007 opened 4 years ago

seadog007 commented 4 years ago

https://github.com/breach-tw/breach.tw/blob/master/verify.php#L14

The verification check if the certain query string is visit. Since some corps' firewall/mail gateway will check links in emails, the verification might be pass even if the email was not exist.

Fix: Should be on page post