|
Posted by Rik Wasmus on 10/13/07 19:24
On Thu, 11 Oct 2007 18:44:51 +0200, kaka <smartestdesign@gmail.com> wrote:
> I am developping a sns site.
> I was wondering if i send user's email addresses as a part of
> confirmation link so that
> when a user receives the confirmation email, he can just click on the
> link to login
> to our site without punching in the password.
No.
What if I know someone's emailadress?
Preferably you use some random unrelated hash for this, which you can
create, store locally, and send out in the email, so it can be rechecked
(and discarded) after comfirmation. Still good for a one-time login, not
reusable or predictable for anyone.
--
Rik Wasmus
Navigation:
[Reply to this message]
|