Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

restrict sign in to browser initiating sign in #2

Open
thoughtafter opened this issue Apr 12, 2019 · 0 comments
Open

restrict sign in to browser initiating sign in #2

thoughtafter opened this issue Apr 12, 2019 · 0 comments

Comments

@thoughtafter
Copy link
Owner

Currently the token can be used from anywhere. It would be possible to store a secret as a cookie so that only the browser initiating the sign in can use the transmitted token. However, this seems like an unlikely threat. The scenario that this seems to fix is an attacker who has not compromised the email but can intercept the email and use it before the user does. This would allow the attacker to access the account.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant