mysterious-van-90907
03/21/2024, 3:39 PMmysterious-van-90907
03/21/2024, 3:39 PMjolly-ocean-27001
03/21/2024, 3:41 PMjolly-ocean-27001
03/21/2024, 3:42 PMjolly-ocean-27001
03/21/2024, 3:42 PMrefined-kangaroo-48640
03/21/2024, 3:52 PMjolly-ocean-27001
03/21/2024, 3:53 PMjolly-ocean-27001
03/21/2024, 3:53 PMrefined-kangaroo-48640
03/21/2024, 3:57 PMjolly-ocean-27001
03/21/2024, 3:58 PMjolly-ocean-27001
03/21/2024, 3:58 PMrefined-kangaroo-48640
03/21/2024, 4:00 PMrefined-kangaroo-48640
03/21/2024, 4:02 PMFor further context, even though we can mitigate the issue on recovery by using OTP, it results in a terrible user experience.
1. User receives an invite
2. Link immediately expires
3. User is redirected to recovery flow (unaware) and has to now do a password reset via OTP
Overall just feels a bit clunky. This wasn't an issue we had with Auth0, I imagine because the links wouldn't expire on access, but rather when they were actually used (recovery actually happens).This sounds like you're first creating a recovery link (with short expiry(?))
jolly-ocean-27001
03/21/2024, 4:02 PMjolly-ocean-27001
03/21/2024, 4:02 PMjolly-ocean-27001
03/21/2024, 4:02 PMjolly-ocean-27001
03/21/2024, 4:06 PMrefined-kangaroo-48640
03/21/2024, 4:09 PMrefined-kangaroo-48640
03/21/2024, 4:09 PMjolly-ocean-27001
03/21/2024, 4:14 PMjolly-ocean-27001
03/21/2024, 4:15 PMjolly-ocean-27001
03/21/2024, 4:15 PMmysterious-van-90907
03/21/2024, 4:16 PM{
"recovery_link": "/ui/recovery?flow=1440ef91-3863-43e7-bb44-ecb64cc2eef3",
"recovery_code": "118217",
"expires_at": "2024-03-22T04:07:16.37783255Z"
}
Will the "recovery_link" not be invalidated if scanned by email scanners? Invalidating the flow ID?refined-kangaroo-48640
03/21/2024, 4:21 PMrefined-kangaroo-48640
03/21/2024, 4:21 PMrefined-kangaroo-48640
03/21/2024, 4:22 PMmysterious-van-90907
03/21/2024, 4:23 PMrefined-kangaroo-48640
03/21/2024, 4:25 PMmysterious-van-90907
03/21/2024, 4:25 PM{{ .RecoveryCode }}
and {{ .RecoveryURL }}
in the email template work?refined-kangaroo-48640
03/21/2024, 4:25 PMmysterious-van-90907
03/21/2024, 4:46 PMmysterious-van-90907
03/21/2024, 5:38 PMrefined-kangaroo-48640
03/21/2024, 6:38 PM.RecoveryURL
is not available in the the OTP recovery template.refined-kangaroo-48640
03/21/2024, 6:41 PMhigh-optician-2097
jolly-ocean-27001
03/22/2024, 9:13 AM