Commit dd6e0dd
security: prevent email enumeration on teacher login
Previously, the login form returned distinct error messages for
"email not found" vs "email not confirmed", allowing attackers to
enumerate registered emails. Now both failure cases silently redirect
to the same "check your email" page without sending an email, identical
to the success response. The distinction is only logged server-side.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent e276628 commit dd6e0dd
2 files changed
Lines changed: 9 additions & 32 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
64 | | - | |
65 | | - | |
66 | | - | |
67 | | - | |
68 | | - | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
69 | 67 | | |
70 | 68 | | |
71 | | - | |
72 | | - | |
73 | | - | |
74 | | - | |
75 | | - | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
76 | 72 | | |
77 | 73 | | |
78 | 74 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
40 | 21 | | |
41 | 22 | | |
42 | 23 | | |
| |||
0 commit comments