The current automagic authentication (implicit creation of authentication cookies, no explicit passwords) is probably fine for many use-cases. It could be enhanced by allowing the users to export their authentication token to other browsers. For mobile devices, a QR code could be used.
For some minimal security, the token transmission should only work once per generated transmission code/link.
The current automagic authentication (implicit creation of authentication cookies, no explicit passwords) is probably fine for many use-cases. It could be enhanced by allowing the users to export their authentication token to other browsers. For mobile devices, a QR code could be used.
For some minimal security, the token transmission should only work once per generated transmission code/link.