Best practices for email confirmation codes

前端 未结 5 606
没有蜡笔的小新
没有蜡笔的小新 2020-12-28 19:46

I\'m creating a PHP website which involves users signing up, and I\'m wondering about best practices for \"email confirmation\" codes.

New users must confirm their e

5条回答
  •  南笙
    南笙 (楼主)
    2020-12-28 20:17

    Why not ask the user to enter their username and their code, thereby eliminating any problem with collision? You don't lose anything security-wise as you're still asking for the key which they'd get from the email, but you'd stop them being able to reset other users' passwords.

提交回复
热议问题