49 karma · joined December 8, 2015
I eat, sleep and breath FusionAuth.
[ my public key: https://keybase.io/robotdan; my proof: https://keybase.io/robotdan/sigs/bZ_z6cHOKMlganpI00p5gb2PN9IkuyCyPpXL5olj8eY ]
Did they build this in house?
I think scripting all of this is great - but also agree that it is important to understand what is being performed.
Looks like a good Friday afternoon hack.
A new virus? Oh, better stock up on Symantec Anti-Virus. How many virus's have been written by those selling you the cure? Security troubles? I'm sure there are plenty of security 'consultants' ready and waiting to take your money.
Maybe I'm too cynical.
Could you put this in an eBook format?
I like how Atlassian does it - they more or less give it away for free for small companies and then once you can afford it they start charging more. Unless I can get going for free, probably a non starter.
Click reset, store a unique id, send the user an email with a link including the unique id, verify that ID on the request and then allow a password change. Then to be secure that unique id needs to be timed out once it is generated to ensure the link is only good for a short period of time, etc.
Not to say anyone couldn't code all of that, but some of the simple features once fully thought out end up being fairly complex. In my experience many of the out of the box options still need to be extended to be fully realized for enterprise usage.
I don't have a ton of experience with DJango specifically so I could be mistaken - perhaps it does more than I know.