---
**[tickets:#8601] email auth verification by link**
**Status:** in-progress
**Milestone:** unreleased
**Created:** Wed Apr 22, 2026 09:43 PM UTC by Dave Brondsema
**Last Updated:** Wed Apr 22, 2026 09:43 PM UTC
**Owner:** Dave Brondsema
With a link we can have a longer token for more security (still type-able if
needed). And the link will defeat some MITM phishing attacks, forcing you to
the right site.
We can apply this to 2FA accounts too (currently being skipped) so they get the
MITM protections too
Downside is if you don't have email access on the same computer you're logging
in to :(
---
Sent from forge-allura.apache.org because [email protected] is subscribed
to https://forge-allura.apache.org/p/allura/tickets/
To unsubscribe from further messages, a project admin can change settings at
https://forge-allura.apache.org/p/allura/admin/tickets/options. Or, if this is
a mailing list, you can unsubscribe from the mailing list.