Skip to content

[Security] Dynamic Email Verification & Password Reset Links - #675

Draft
shhzhang wants to merge 1 commit into
bs-community:devfrom
shhzhang:fix20260124
Draft

[Security] Dynamic Email Verification & Password Reset Links#675
shhzhang wants to merge 1 commit into
bs-community:devfrom
shhzhang:fix20260124

Conversation

@shhzhang

Copy link
Copy Markdown

Problem

  1. Static Signature Vulnerability:
    • Email verification links used a static signature algorithm (same link for lifetime), allowing account hijacking if links were leaked.
    • Worst-case scenario: Compromised AppKey + leaked link → full-site account under danger.
  2. Overly Long Reset Window:
    • Password reset links remained valid for 1 hour, enabling attackers to hijack accounts if intercepted.
    • Worst-case scenario: Compromised AppKey + leaked link → full-site account account take over.

Solution

  • Email Verification:
    • Replaced static signatures with HMAC-SHA256 + timestamp + nonce.
    • Links are now one-time-use and expire immediately after verification.
  • Password Reset:
    • Links are now one-time-use and expire immediately after verification.

Impact

  • Closed Communities: Critical for real-name systems (e.g., gaming, enterprise).
  • AppKey Leak Mitigation: Even with leaked AppKey, intercepted links are now useless.

The commit message is translated by Deepseek due to my poor English. Please do pardon me.

 **Problem**
1. **Static Signature Vulnerability**:
   - Email verification links used a static signature algorithm (same link for lifetime), allowing account hijacking if links were leaked.
   - *Worst-case scenario*: Compromised AppKey + leaked link → full-site account under danger.
2. **Overly Long Reset Window**:
   - Password reset links remained valid for 1 hour, enabling attackers to hijack accounts if intercepted.
   - *Worst-case scenario*: Compromised AppKey + leaked link → full-site account account take over.

 **Solution**
- **Email Verification**:
  - Replaced static signatures with **HMAC-SHA256 + timestamp + nonce**.
  - Links are now **one-time-use** and expire immediately after verification.
- **Password Reset**:
  - Reduced validity window from 1h → **5 minutes**.
  - Added rate limiting to prevent brute-force attacks.

 **Impact**
- **Closed Communities**: Critical for real-name systems (e.g., gaming, enterprise).
- **AppKey Leak Mitigation**: Even with leaked AppKey, intercepted links are now useless.

The commit message is translated by Deepseek due to my poor English.
@shhzhang
shhzhang marked this pull request as draft January 26, 2026 15:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant