This sucks when the link is a one-time-use only code.
This sucks when the link is a one-time-use only code.
To be honest the original process we had maybe wasn't 100% perfect - users can double click links for example, and would see a message that the link had "expired". So from a UX perspective we maybe should've had the extra confirmation step before activation/reset to begin with. But I'm in two minds over email providers following all the links in your emails, it feels a bit creepy
Isn't that pretty much the definition of "confirming your email address" transactional emails? Wouldn't really call this "sneaky".
However, the absence of a bounce probably also does that, albeit less reliably.
Those are meant to load a page with a confirmation form that makes a POST request. The GET link can still expire over time, but must never be expired from a GET request: you never know when a link preview bot is going to follow links.