]> git.vanrenterghem.biz Git - git.ikiwiki.info.git/commitdiff
update re passwordauth @
authorJoey Hess <joeyh@joeyh.name>
Thu, 14 May 2015 14:41:07 +0000 (10:41 -0400)
committerJoey Hess <joeyh@joeyh.name>
Thu, 14 May 2015 14:41:07 +0000 (10:41 -0400)
doc/todo/emailauth.mdwn

index aac2c988e93b2a245961f1871a4773577365eed9..88096bee1ed799603050450a9885930a387ba2d2 100644 (file)
@@ -62,7 +62,7 @@ Implementation notes:
   Otherwise, someone could use passwordauth to register as a username that
   looks like an email address, which would be confusing to possibly a
   security hole. Probably best to keep passwordauth and emailauth accounts
-  entirely distinct.
+  entirely distinct. Update: passwordauth never allowed `@` in usernames.
 * Currently, subscription to comments w/o registering is handled by
   passwordauth, by creating a passwordless account (making up a username,
   not using the email address as the username thankfully). That account can be