|
|
|
|
|
by RulerOf
1477 days ago
|
|
>Your login attempt would keep the login (not logged-in) session open wherever you attempted to login from While I generally agree that this behavior is correct from a usability standpoint, it's not safe. That design allows a user to do a one-click account compromise when they receive a magic link that was sent in response to the login attempt of an attacker that happened to know the user's email address. |
|