Show HN: Log in to WordPress via QR code (fully functional plugin available)
jackreichert.com
jackreichert.com
Username/password are never passed back and forth, only the unique hash.
Hash is removed from the database once it’s used, old hashes that haven’t been used can’t be unless the database is hacked, but then you have bigger issues.
All database queries of the hash have been escaped to prevent XSS attacks.
Aside: God, imagine if browser vendors had put a tiny bit of effort into password management or even just the UI around http auth back at the beginning. All sites could use http auth or whatever superceded it instead of their own login forms and this problem would seem just as stupid as it actually is.
Still that means I probably use one maybe twice a month, but I would use them more if they were more widespread.
I expect most people are the same, no one types long URLs into their phones while reading them off a newspaper or billboard or store window do they?
I had an instant conversation topic with me at all times and people seemed to appreciate the creative use as well.