franklindyer / agora-app

Simple and (hopefully) secure social media application. Also a project for spring 2024 CS 444 cybersecurity class at UNM.
4 stars 1 forks source link

Recovery tokens should be in-site, not in emails #102

Closed franklindyer closed 3 months ago

franklindyer commented 4 months ago

Delivering recovery codes to users' inboxes in plaintext is a security weakness. Instead, a one time link should be delivered to users' inboxes, through which they can visit a page on the site that will show them their recovery code only once. After leaving that page, it is up to the user to have stored the recovery code in a safe place.

franklindyer commented 3 months ago

closed by #103