Matthew
@matthew
I don't understand what it means to "sign in" to a mini app on warpcast. Doesn't that defeat the purpose? it's supposed to automatically know who you are. Should users sign in right when the mini app opens? when they tap the "rsvp" button?
5 replies
2 recasts
10 reactions
blaynem
@drilkmops
It’s incredibly simple to fake a user id on warpcast. Good security practice would be to ask you to sign in
1 reply
0 recast
0 reaction
Matthew
@matthew
Yeah I know, but warpcast used to send a signed payload when you first open the app that lets you authenticate without having to sign in. It's a much better experience for the user IMO.
1 reply
0 recast
0 reaction
blaynem
@drilkmops
I 100% agree it’s a better UX to not require an additional one! Would love to not need it, but I take security with crypto way more seriously.
0 reply
0 recast
0 reaction