Skip to content
This repository has been archived by the owner on Nov 30, 2021. It is now read-only.

Don't disclose having an email in storage through signup #63

Open
markuswustenberg opened this issue Sep 29, 2020 · 0 comments
Open

Don't disclose having an email in storage through signup #63

markuswustenberg opened this issue Sep 29, 2020 · 0 comments

Comments

@markuswustenberg
Copy link
Member

Currently, a signup attempt with a duplicate email address results in an error, so an attacker can figure out whether an email is associated with a user.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant