Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NativeAuth Update #3146

Open
wants to merge 1 commit into
base: minor
Choose a base branch
from
Open

Conversation

d46
Copy link
Contributor

@d46 d46 commented Oct 18, 2024

Description

Follow up PR for the #2786

Breaking changes

registerCustomerAccount now returns EmailAddressConflictError if the customer has no user and no nativeAuth method. The method logic has been simplified with early termination. I removed the token refreshing logic from the first PR, as I believe it should not be the concern of the registration method.

For enumeration attacks, several types of enumeration attacks are possible. Addressing them at the application-wide or software level may not be the best approach. Handling them at the load balancer level could be a more effective solution.

Checklist

📌 Always:

  • I have set a clear title
  • My PR is small and contains a single feature
  • I have checked my own PR

👍 Most of the time:

  • I have added or updated test cases
  • I have updated the README if needed

Copy link

vercel bot commented Oct 18, 2024

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Updated (UTC)
docs ✅ Ready (Inspect) Visit Preview Oct 18, 2024 4:21pm

@d46 d46 changed the title fix(chore): Return account conflict error for NativeAuth registration… NativeAuth Update Oct 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant