aboutsummaryrefslogtreecommitdiff
path: root/doc/bugs/Unable_to_access_pagespec_preferences_on_https:__47____47__joeyh.name__47__/comment_1_8e26ec8941be9f6b16cec97281df7aaf._comment
blob: 940366a7c88751f27be524b48c9e0b12baa99f82 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
[[!comment format=mdwn
 username="joey"
 subject="""comment 1"""
 date="2018-12-12T14:40:46Z"
 content="""
Sending an auth token with every notification email would
not be good from a security POV.

But, the ikiwiki username that has subscribed could be included in the
emails; the url to the prefs could possibly even have it prefilled
(unless CSRF protection or something prevents that).

> I think now when I login via either method I'm accessing the account with a username

No, ikiwiki accounts are not connected like this. If you log in with the
old account it will have separate subscription prefs than the new account.
"""]]