-
Notifications
You must be signed in to change notification settings - Fork 4.4k
Open
Labels
NEW_CSIssue about the creation of a new cheat sheet.Issue about the creation of a new cheat sheet.
Description
Problem Statement:
Developers frequently mis-handle email validation, canonicalization, and verification flows in identity systems, leading to account takeover and enumeration risks.
Why This Needs Its Own Cheat Sheet:
Authentication CS is large.
Input Validation CS does not address identity specific email handling risks.
Proposed Scope:
Email format validation pitfalls
Canonicalization and normalization
Unicode and IDN concerns
Case sensitivity handling
Email ownership verification flows
Password reset threat model
Email change workflows
Anti enumeration controls
Temporary email abuse
Email as weak factor risks
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
NEW_CSIssue about the creation of a new cheat sheet.Issue about the creation of a new cheat sheet.