c/security › command
0votes

Harden authentication flowsPromptLow risk

submitted by u/client to c/security · 0 copies

Review sign-up, login and reset flows for common account takeover holes.

Prompt · 1 variable
Review the authentication flows in {{app_or_code}} (sign-up, login, password reset, email change, session handling).

Check for:
- User enumeration via different error messages or timings.
- Missing rate limits / lockouts.
- Reset tokens that are guessable, long-lived or reusable.
- Email change without re-authentication or confirmation to the old address.
- Sessions not revoked after password change.
- Missing MFA option for admins.

For each issue: the risk, a realistic attack, and the fix with code.
0 commentsreport
0 comments

Log in to join the discussion.