How to deal with social login flow in my site - problematic flow and best practices

Viewed 180

So I read a lot about social login on the web. The problematic flow is:

1) User sign up with regular email

2) User sign in with Social (Facebook, Google, etc.) What should I do?

If the social email is different from its original email, that's ok, for me it's a different account. But, if the email is the same, I'm acting like it's the same user.

The problem is the following scenario:

1) User signup with regular email

2) An attacker signup to Social with the user email (without email verification)

3) The attacker can log in to my system as the User.

So the question here is, are there main socials (facebook, google, ...) that allow social login to other site, without verify the user's email?

What do you think? Thanks!

1 Answers

Most sites actually just map social snowflake values to user ids. For example the flows would go like this:

Here is the flow if the user signs up with email

  1. User signs up with regular email
  2. User can now link their social to regular account to login with social (email doesnt have to match)
  3. Profit

Here is the flow if the user signs up with a social

  1. User signs up with social
  2. Use social to autofill normal account fields
  3. Ask for any additional fields needed (leave password null if you like to require social login)
  4. Link social snowflake value to existing account.

If you need any clarification ask but I tried my best to explain :)

Current providers that are considered 'safe' for the problematic flow you are mentioning would be Google and Microsoft (including Azure AD) to my current knowledge.

Related