Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Account Recovery Email Challenge Flow #528

Open
matheus23 opened this issue Jun 17, 2021 · 2 comments
Open

Account Recovery Email Challenge Flow #528

matheus23 opened this issue Jun 17, 2021 · 2 comments

Comments

@matheus23
Copy link
Member

Tracking here that we should at some point define how recovery email sending should work.
Resending account recovery emails is desirable because the user might have accidentally deleted the email they got/it landed in some kind of spam folder/they can't find it anymore.

According to @bmann there's going to be some state tracking involved in the account recovery flow in general:

There’s some state here
“Recovery Email Sent with handshake code X, Email clicked on / received, Recovery Complete / one BLS key burned”
Because future, like OTP resets you might have multiple BLS codes

Ideally we define flows around this.

@bmann
Copy link
Member

bmann commented Jun 17, 2021

Haha. Well “according to bmann” that’s just what I thought of on the fly ;)

Thanks for capturing.

@matheus23
Copy link
Member Author

@therealjeffg

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants