souramoo / commentoplusplus

Commento with out of the box patches and updates to add useful features and fixes. Also with one-click deploy to Heroku so you can get up and running fast.
MIT License
389 stars 62 forks source link

E-Mail Login verification #153

Open ykorzikowski opened 10 months ago

ykorzikowski commented 10 months ago

Hi there,

I just noticed even if anonymous login is disabled users can login using a random e-mail/password combo and start posting.

It should be not possible to post comments /l ogin until the e-mail has been verified by clicking a link send to the users mail account.