Homestyx hydra

R1:6232e9676cd4

Don't send reset links to unverified addresses on accounts with verified addresses

Summary:
Via HackerOne. If a user adds an email address and typos it, entering `alinculne@gmailo.com`, and it happens to be a valid address which an evil user controls, the evil user can request a password reset and compromise the account.

This strains the imagination, but we can implement a better behavior cheaply.

- If an account has any verified addresses, only send to verified addresses.
- If an account has no…
Repository: R1 hydra
Commit Date: Aug 11 2014