-
Notifications
You must be signed in to change notification settings - Fork 26
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Send meld request #8
Comments
I think it makes sense, but still if the email address is the same and it is verified for both accounts there should be no problems... Btw, I'm open to whatever proposal that can improve security! One more thing to consider is that the app owner might want to prevent the creation of many different accounts by the same user (for him not to gain discounts and offers more than once). In this case, asking the user whether to meld or not does not fit well I guess... thoughts? |
So far I have only seen google accounts have a verified option but I guess yes in that case its fine. Maybe still send an email but it only tells the use of the event and does not require action. Just to maintain constancy.
Oh! Yes that would be nice. In that case you can still send the the meld request. If the user says this is not their account then we could set up some way to mark that account as blocked, optionally of course. But it's worth notting that making more emails/service accounts is very easy and users will still get around this. |
...mmm, I think now I see what you meant... So there could be no Is this what you meant? |
Again, sorry for the late response. Yes thats one of the use cases. But even when its a meld it should be able to send the user an email that warns them of whats happening and even requires confirmation before the meld. |
the confirmation step is already in place. The best thing would probably be to add another callback so to let developers send emails to warn the user and ask for confirmation. The confirmation step should also be easy to implement (see this stub package...) I admit this package deserves more love! ;-) ...still, so much ideas and good interactions with the community (you at first, tnx!), but my spare time is very limited :( I might try to write things down somewhere, so to see whether better collaborations could arise. Tnx, as usual! |
So a thought on security. Rather then just checking if the local email is verified would it not be better to send a meld accounts request email?
In the email it could say something like:
The text was updated successfully, but these errors were encountered: