• zaphod@sopuli.xyz
      link
      fedilink
      arrow-up
      36
      ·
      1 month ago

      It’s quite simple actually: The user wanted to delete their account, but forgot their password so they requested a password reset. Before the password reset email was delivered, the user remembered their password and deleted their account. The password reset email is finally delivered and apparently some email clients open all the links in the background for whatever reason, so it wasn’t actually the user who clicked the password reset link.

        • Malix@sopuli.xyz
          link
          fedilink
          arrow-up
          19
          ·
          edit-2
          1 month ago

          Yep. Apparently outlook does this and afaik because some kind of link sniffing/scam detection/whatever, but it does it by changing the first characters of each query argument around.

          We spent amazingly long time figuring that one out. “Who the hell has gotten Microsoft service querying our app with malformed query args and why”