Matthew pfp
Matthew
@matthew
I don't understand what it means to "sign in" to a mini app on warpcast. Doesn't that defeat the purpose? it's supposed to automatically know who you are. Should users sign in right when the mini app opens? when they tap the "rsvp" button?
5 replies
2 recasts
10 reactions

blaynem pfp
blaynem
@drilkmops
It’s incredibly simple to fake a user id on warpcast. Good security practice would be to ask you to sign in
1 reply
0 recast
0 reaction

Matthew pfp
Matthew
@matthew
Yeah I know, but warpcast used to send a signed payload when you first open the app that lets you authenticate without having to sign in. It's a much better experience for the user IMO.
1 reply
0 recast
0 reaction

blaynem pfp
blaynem
@drilkmops
I 100% agree it’s a better UX to not require an additional one! Would love to not need it, but I take security with crypto way more seriously.
0 reply
0 recast
0 reaction