Skip to content

Should we store a digest of confirmation_token?ย #612

Open
@tute

Description

Do you think it's worth it to store a digest of the confirmation_token, so that access to the database doesn't grant easy access to user accounts?

One problem is that it would be a backwards incompatible change, and would require a migration of existing data.

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions