logoalt Hacker News

argeeyesterday at 7:03 PM0 repliesview on HN

> In general it's bad practice for a user to expose someone else's email address to an application provider without consent

Thanks, that makes sense as a rule of thumb. I'll move towards invite code (and work domain/SSO) based access. It's also a bit awkward to be able to add existing users to a workspace without any sort of confirmation, so my system needs a bit of rework regardless.