Hacker News new | ask | show | jobs
by rbinv 4301 days ago
> - anyone can login to dashboard with a non registered email or non-email http://retentionbooster.com/site/adduser?email={random}&pass....

Does not seem to happen, here (shows the home page). Maybe you're cookied/logged in?

> - make sure the retention email doesn't end up in spam folder

That's not really up to him (except, of course, for basic sender stuff like SPF and DKIM).

1 comments

- login (use something like http://retentionbooster.com/site/adduser?email=a43abe&passwo...)

- choosing a good transactional email service might be helpful.

That's a pretty good idea (as long as these are considered "transactional" by the provider).

edit: Can confirm the authentication behavior now.

edit 2: In fact, the username is printed without any escaping.