interfacerproject / interfacerproject/zenflows
Mitigate fake email sign-up request: throttling of unsigned API calls and/or captcha
Open
@protodeniz is already working on this.
Since Jul 27, 2022.
- Dominant language
- Elixir
- Stars
- 18
- Forks
- 4
- Avg merge
- 7m
- Merged PRs (30d)
- 2
Description
Problem: when signing up, the client sends an unsigned mutation containing an email. A hacker can use this to send N mutations containing emails from a list, to figure out which email is registered in Zenflows.
Ways to mitigate this are:
- throttling of unsigned API calls
- implementing a captcha
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.