Skip to content

Require password when deleting account#1054

Open
Toastbrot236 wants to merge 3 commits intoLittleBigRefresh:mainfrom
Toastbrot236:delete-check
Open

Require password when deleting account#1054
Toastbrot236 wants to merge 3 commits intoLittleBigRefresh:mainfrom
Toastbrot236:delete-check

Conversation

@Toastbrot236
Copy link
Contributor

For security reasons, this PR makes requests to the user's own account deletion endpoint require a body with a SHA512 hash of the user's password, regardless of whether they are already authenticated. This does alter APIv3 spec, but it's likely not a widely used endpoint. A complementary PR for the refresh-web legacy branch will be opened alongside this one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant