ostap
After opening a magic link, the user must click a confirmation button to log in and invalidate the token. I assume this exists to prevent email scanners from consuming links.
Could this be automated with a short JS setTimeout that submits the confirmation request automatically? Or is this a bad idea? I assume that scanners only fetch the HTML and don’t always have a headless browser or keep it open for long.
Current behaviour after the registration link is opened:
Current behaviour after the login link is opened:
mix phx.new example --module=Example --database=sqlite3 --no-live
cd example
mix ecto.create
mix phx.server
mix phx.gen.auth Accounts User users # n - Using Phoenix.Controller only
mix deps.get
mix ecto.migrate
mix phx.server
Trending in Questions
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
Documentation
While reading the Scoped Routes section, I noticed that the documentation currently refers to a problem without explainin...
New
Hello,
I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind.
However, when I launch mix phx.server, I get an error...
New
Hi everyone,
I am toying with the idea of building a “match maker” for giving personal help to people that wants to start coding.
I sta...
New
I’m working on a small exercise involving update_in/3, and I came up with this solution:
data = %{
name: "Periodic Table",
category:...
New
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication):
toke...
New
Is there any way to avoid the Hologram compiler running when using iex? It seems like the front-end code could potentially be disregarded...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
I am happy to introduce the very α version of the new programming language compiled to BEAM.
Welcome Cure.
It has literally three kille...
New
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
A little off-topic, but I feel like people here have a good head on their shoulders.
I used to be quite good at making software. Was luc...
New
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ai
- #ecto-query
- #elixirconf-us
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #metaprogramming
- #hex












Showing Posts 1 to 2- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
garrison
I would say this is a dangerous assumption. If the scanners don’t use a headless browser that would make it trivial for bad actors to bypass the scanners with a simple React app. Given that the scanners and the bad actors are locked in an endless back-and-forth my guess would be that the scanners have been running JS for a while.
There is a mutual understanding between the scanner developers and web developers that scanners will not issue POST requests. Everyone is on the same page about this, so it is unlikely to change.
On the other hand, if you design a login page using some timeout, even if you test to ensure that it works today the scanner could always change its behavior tomorrow and break your website while you’re asleep.
I think it would be wise to stick with the standard method.
ostap
Thank you! Decided to try a slightly riskier/novel approach:
My BotD library fork detects whether the visitor is not a bot (headless chromium), and only then will the form be submitted automatically.
I think it’ll be worth it as a UX improvement. But we’ll see if anyone complains
; it’s a small side project where I’m testing this out.