Security Issue: User Impersonation

I think this process is safe. When they click on the link, they are automatically logged into Softr.
The confirm button also records the logged-in user who clicked the button.
I only show this block to logged-in users, non-authorised users won’t be able to see it. Even if they could click it, it would log anything, and they would just see empty values.

Here’s an idea to improve email verification for external user sign ups. What do you think?

1 Like

Hi Artur. Any update on this? It wasn’t on the list of upcoming releases on the Business/Pro webinar last Monday.

Hi @Suzie,

Is this still on the radar?

Hey folks, we are now revisiting the whole user registration workflow where we will have invite-only and/or public apps, and for public apps, we will be including email verification as an option.

@artur, email verification nor public vs internal sign up are on your roadmap.

They are in… our product team is working on it, it still needs to go through review/design and then get into implementation…

Thanks for clarifying @artur, it is indeed listed. How useful this is for builders’ planning, is not even a question anymore though, at least from many in the community. We simply can’t plan or do anything useful with “Later”, let alone “Next”.

Let me share that feedback :slight_smile: