Hacker News new | past | comments | ask | show | jobs | submit login

Super scratch-notes version:

- Use sendgrid to send emails, it'll be free at your usage

- Make the login form only accept an email address, dont risk saving passwords, display a generic "if you signed up you'll get an email soon" message on submission for all values.

- Whitelist your buddies' emails, send them a link to login with. Ignore the rest.

- The link can be a UUID without the dashes or something similarly sufficiently random (could sha1 hash the time and be good enough for your purposes). yourdomain.com/login/somesufficientlyrandomandlongkey

- Save that key in the DB, that's effectively the password. Delete stuff after a while so they have to re-login.

Feel free to hit me up on Keybase or whatever (details in my profile) if you want to follow up in detail.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: