Auto-login Link Security

Niamh Ferns Updated by Niamh Ferns

Auto login tokens are similar to the Global Magic tokens, as both raise security concerns:

  • If the email receiver forwards the email to other people, then they could use the token to log in before it expires.
  • If the email receiver CC's someone when replying to it, the people from the CC list can see the login link.
  • After the email receiver replies to the ticket email, the replies are added to the ticket's attachment and note. Thus, the auto login token is saved in places outside of a user's email inbox.

    This is the reason why Microsoft Teams or GitHub issue update emails never contain any auto-login token.

How did we do?

Contact