|
|
|
|
|
by AlchemistCamp
1782 days ago
|
|
> "This sounds like it would break a bunch of email address verification systems, password recovery links and the like." This is exactly the pain I've experienced with my own site, https://alchemist.camp I've manually tested it and seen the token consumed when clicking the link via gmail but had no issues when copying the link from the password reset email to a gmail account. A second manual tester confirmed the same, as have multiple support cases. Password recovery links sporadically fail for gmail users. I had to add extra instructions to copy and paste rather than click through the link and am in the process of moving away from single-use tokens because a lot of people still click before reading those instructions and email me for support. My increased customer support burden isn't something Gmail PMs worry about, but they may whitelist some larger service's emails. |
|