Skip to content

Email Invite Warning #1685

Answered by tommoor
dmezh asked this question in General
Discussion options

You must be logged in to vote

You can see by the comment directly below that line that it's purposefully built this way, returning a success/failure allows enumeration of user accounts and would be considered a small security flaw.

I think the ideal solution would be to send an email to the address if they don't have an account letting them know to request an invite. Such an email would need to be protected by a rate limiter though.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dmezh
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants