-
Notifications
You must be signed in to change notification settings - Fork 373
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: add option to disable magic links #1756
Conversation
015fc95
to
c9eefd9
Compare
Pull Request Test Coverage Report for Build 10664277986Details
💛 - Coveralls |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can consider blocking generateLink as well.
It’s an admin method though so maybe it should be expected to work independent of whether magic link is disabled. We can also consider proceeding as follows and document that disabling magic links doesn’t disable creation of the link via GenerateLink
Generate link is used to generate a link that is sent separately from the Auth server, so that's fine. This only blocks magic links generated from the endpoint. |
Yup, that makes sense - let's document that the toggle only blocks magic links generated from the endpoint then. |
🤖 I have created a release *beep* *boop* --- ## [2.160.0](v2.159.2...v2.160.0) (2024-09-02) ### Features * add authorized email address support ([#1757](#1757)) ([f3a28d1](f3a28d1)) * add option to disable magic links ([#1756](#1756)) ([2ad0737](2ad0737)) * add support for saml encrypted assertions ([#1752](#1752)) ([c5480ef](c5480ef)) ### Bug Fixes * apply shared limiters before email / sms is sent ([#1748](#1748)) ([bf276ab](bf276ab)) * simplify WaitForCleanup ([#1747](#1747)) ([0084625](0084625)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Adds an option to disable magic links, as they are more prone to email sending abuse than other email authentication methods.
🤖 I have created a release *beep* *boop* --- ## [2.160.0](supabase/auth@v2.159.2...v2.160.0) (2024-09-02) ### Features * add authorized email address support ([supabase#1757](supabase#1757)) ([f3a28d1](supabase@f3a28d1)) * add option to disable magic links ([supabase#1756](supabase#1756)) ([2ad0737](supabase@2ad0737)) * add support for saml encrypted assertions ([supabase#1752](supabase#1752)) ([c5480ef](supabase@c5480ef)) ### Bug Fixes * apply shared limiters before email / sms is sent ([supabase#1748](supabase#1748)) ([bf276ab](supabase@bf276ab)) * simplify WaitForCleanup ([supabase#1747](supabase#1747)) ([0084625](supabase@0084625)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Adds an option to disable magic links, as they are more prone to email sending abuse than other email authentication methods.
🤖 I have created a release *beep* *boop* --- ## [2.160.0](supabase/auth@v2.159.2...v2.160.0) (2024-09-02) ### Features * add authorized email address support ([supabase#1757](supabase#1757)) ([f3a28d1](supabase@f3a28d1)) * add option to disable magic links ([supabase#1756](supabase#1756)) ([2ad0737](supabase@2ad0737)) * add support for saml encrypted assertions ([supabase#1752](supabase#1752)) ([c5480ef](supabase@c5480ef)) ### Bug Fixes * apply shared limiters before email / sms is sent ([supabase#1748](supabase#1748)) ([bf276ab](supabase@bf276ab)) * simplify WaitForCleanup ([supabase#1747](supabase#1747)) ([0084625](supabase@0084625)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Adds an option to disable magic links, as they are more prone to email sending abuse than other email authentication methods.