[opensource-dev] separation between login id and publicly visible id(s)

Tateru Nino tateru.nino at gmail.com
Mon Aug 23 12:12:36 PDT 2010



On 24/08/2010 4:51 AM, Joel Foner wrote:
>
>     As Josh and others have said, one of the things we'd need is a
>     unique secret account identifier. Unfortunately the only existing
>     account datum which might work here is email address, and that's
>     not unique, though we're starting to think that it really should be
>
>
> Just a quick note... email addresses change fairly regularly. Basing 
> the permanent unique account identifier on a transient token seems 
> bound to create problems in the longer term due to user movements from 
> one email address to another, and old addresses become invalid and 
> even forgotten by users.
>
Actually, I remember that the RegAPI (for a long time - don't know if it 
still does) wouldn't accept an email address that had /ever/ been used 
for registration of an account previously. Ran into that one during some 
client work.

-- 
Tateru Nino
http://dwellonit.taterunino.net/

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.secondlife.com/pipermail/opensource-dev/attachments/20100824/e4d0b376/attachment.htm 


More information about the opensource-dev mailing list