top | item 33732474

(no title)

gamzer | 3 years ago

If the goal is to log in new users immediately after registration, is it possible to not leak whether a username is already registered?

If hn@example.com is not registered and I register it, I will be logged in (even if it does not belong to me).

If hn@example.com is already registered, the site can neither let me register it nor log me in.

discuss

order

No comments yet.