open-company / open-company-web

OpenCompany Web Application - Carrot web UI
https://github.com/open-company
Other
61 stars 9 forks source link

Invite only verified #1181

Closed bago2k4 closed 2 years ago

bago2k4 commented 2 years ago

Part of: https://trello.com/c/YBJz95A6

Review with: https://github.com/open-company/open-company-auth/pull/110

NB: this is already live on production

Description: This was a quick change needed to avoid "hackers" (if we can call them such) send tons of invites to potentially non-existing email addresses via our UI. Until now you could sign up on Carrot and start inviting people, initially it was good to decrease our user's friction but now it revealed to be a security hole since it can get our SES account suspended.

To test: