On 24/08/2010 4:51 AM, Joel Foner wrote:

    As Josh and others have said, one of the things we'd need is a
    unique secret account identifier. Unfortunately the only existing
    account datum which might work here is email address, and that's
    not unique, though we're starting to think that it really should be


Just a quick note... email addresses change fairly regularly. Basing the permanent unique account identifier on a transient token seems bound to create problems in the longer term due to user movements from one email address to another, and old addresses become invalid and even forgotten by users.

Actually, I remember that the RegAPI (for a long time - don't know if it still does) wouldn't accept an email address that had /ever/ been used for registration of an account previously. Ran into that one during some client work.

--
Tateru Nino
http://dwellonit.taterunino.net/

_______________________________________________
Policies and (un)subscribe information available here:
http://wiki.secondlife.com/wiki/OpenSource-Dev
Please read the policies before posting to keep unmoderated posting privileges

Reply via email to