-
-
Notifications
You must be signed in to change notification settings - Fork 118
Open
Description
In O-auth login route, I could see that the Mongo DB was checked against a user name existing in the DB as returned from Google Servers. Does this not allow any user to create an email ID with the same name as an existing user and gain access into their accounts? Would email be a better parameter to check against?
Metadata
Metadata
Assignees
Labels
No labels