I am currently testing django-allauth for one of my applications.
So far it seems to be a very good third party package.
One thing is concerning me - the workflow of adding new Email Addresses / Changing primary.
Let me explain:
Imagine someone gets to access to your account for a brief moment; you could be in the restroom and still be logged in.
A new Email is being added by this "rogue person" and verified.
Now he is able to just change it to "Primary" and delete your old Email.
He has now full access to the account, since "Forgot your password" will work with the new Primary mail.
Is there a good way to prevent such behaviour?
e.g. when changing to a new primary mail address this step has to be confirmed first via an email token
or:
Adding a new email addresses requires an password input first.
与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…