Over at PatientWallet.com, they got several things wrong. First, after I entered my new address and saved the change, it popped up a dialog asking me to enter my password to confirm, _and the password field was already filled in._ I do _not_ have any sort of autofill enabled in my password manager. I have no idea how or why this happened, but however it happened, it's really broken. (continued)
#ChangeOfAddress
🧵
More PatientWallet.com... After I changed my address, the site sent a single confirmation email to both my old and new addresses; the new address was in the To line and the old address was BCC'd. This is a bad idea for several reasons, the biggest one being that not including the recipient address in the To header increases the spam score of the message significantly, so it's more likely to end up in the user's spam folder. (continued)
#ChangeOfAddress
🧵
More PatientWallet.com... In addition to the address change notification, the site also sent a separate, entirely redundant and unnecessary "Your PatientWallet user details have been changed" message.
Also, both this and the email address change notification were sent _before_ the "Please verify your email address" message was even sent, let alone before I clicked the link in that message to confirm the change. (continued)
#ChangeOfAddress
🧵
More PatientWallet.com... When I clicked the link in the "Please verify your email address" message to confirm the new address, the site loaded, and there was a banner at the top telling me that I needed to confirm my address, _which I had just confirmed by clicking on the link which brought me to that page_.
This is some amateur hour stuff, seriously.
#ChangeOfAddress
🧵
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.