Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is this maintained / being used in production? #128

Open
daan241 opened this issue Jan 19, 2023 · 1 comment
Open

Is this maintained / being used in production? #128

daan241 opened this issue Jan 19, 2023 · 1 comment

Comments

@daan241
Copy link

daan241 commented Jan 19, 2023

Hi,
Is anyone (still) using this in production? It appears to be the most popular django passwordless / magic link package, but multiple security risks/improvements do not seem to get resolved: merging PR #86 (or #63) or integrating rate limiting / limited attempts (#100)?

(I found an earlier topic on this, where @aaronn indicated he was open to PR's, so I wonder if that got outdated?
#98 (comment)

@daan241 daan241 changed the title Is this maintained / being used? Is this maintained / being used in production? Jan 19, 2023
@sergioisidoro
Copy link

sergioisidoro commented Apr 23, 2023

I was about to take a shot at couple of fixes to improve this project that especially impact me (eg non US numbers and standardising phone numbers to E164), but seeing some critical issues like #131 taking months to merge, I decided to make a proposal based on this project in Djoser to implement these features - sunscrapers/djoser#725

It tries to fix a couple of things that have been proposed and suggested here, such as variable token length, standalone tokens, configurable serialisers, and configurable permissions.

While I totally understand and support the author's decision to update this lib only when they need it (tbh I think that's the only sane way of managing a open source repo by yourself - to build it for yourself), I feel discouraged to contribute when so many pull requests are on hold, so I hope the author does not take it personally that I take inspiration on his work to port this functionality to another project.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants