rails-security-checklist
rails-security-checklist copied to clipboard
Invalidate any account credentials received over plain HTTP
Consider guideline to invalidate any credentials received over plain HTTP. Consider sending courtesy email to account owner?