Yeah, that's a risk. I'm mitigating it by having the token expire shortly (30 minutes for now) and one-time-use (not implemented yet)

Ripping out all that password validation code felt good.

ALTER TABLE "users" DROP COLUMN "password_hash"

:)

Thanks to the simplicity of the auth solution in this particular project, I was able to implement a passwordless email token based solution in about an hour. :)

Yeah. I feel for you, but you have to remember he probably doesn't know (or if he did, he probably forgot) that context. It doesn't help that she deleted all her posts, hah

Everyone uses everything in different ways. But yeah, that latest outburst of WHERE ARE THE NUMBERS was kind of weird.

Maybe he's busy with you know, real life. :P

Network is iffy sometimes, yeah. I'm not going to be saturating 100mbps 24/7 anytime soon, and I have a CDN anyways. It's not a big problem at this stage.

Hi there