Let’s gooooooooo

  • eroc1990@lemmy.parastor.net
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 year ago

    Not a bad idea! The attack vector issue they mention in the PR comments is valid, though. Not displaying those errors gives an attacker no confirmation that a user whose account they’re trying to attack exists, if they’re trying known used passwords. But good on you doing what you can to contribute to the project!

    • Venator@kbin.social
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      There should be an error, but it shouldn’t say whether it was the email or password that was wrong.