The user is redirected to the Firefox Monitor homepage after refreshing the unsubscribe page #355
Comments
|
@groovecoder @lesleyjanenorton I think the "you are no longer subscribed" view should be separate from /user/unsubscribe - why not serve it as a static page or something so that the browser doesn't ask to resend post data? |
|
@nhnt11 interesting ... In my head I'm avoiding any pages that say something like "You are no longer subscribed" (I'm still not sure I like the "This email address is not subscribed to Firefox Monitor") because I'm extra paranoid about user enumeration against this service. (@psiinon @moz-jvehent - should I be this paranoid?) I think @lesleyjanenorton has a fix incoming for this though. |
|
This is closed as of #406. Note: the intended behavior is now that refreshing the unsubscribe form after submitted feedback should show the user an error |
Probably. User enumerations aren't the worst of attacks, but since this is a security service, I think it's fair to take extra precautions. |
|
Cool, @groovecoder, I didn't mean to draw attention to the language, I was just using that phrase to identify the view I was talking about :) Anyway, looks like this has been taken care of! |
[Affected versions]:
[Affected Platforms]:
[Prerequisites]:
[Steps to reproduce]:
[Expected result]:
[Actual result]:
[Regression]:
[Additional info]:
The text was updated successfully, but these errors were encountered: