docs: update going into prod with section on email scanners (#11725)

* Update going-into-prod.mdx

* Update apps/docs/pages/guides/platform/going-into-prod.mdx

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This commit is contained in:
Joel Leeandgithub-actions[bot] authored and GitHub committed 2023-01-20 14:32:58 +08:00
1 parent 10963e5e1d
commit 5ee396336e
1 file changed
+5
@@ -73,6 +73,11 @@ After developing your project and deciding it's Production Ready, you should run
- Supabase provides CAPTCHA protection on the signup, sign-in and password reset endpoints. Please refer to [our guide](/docs/guides/auth/auth-captcha) on how to protect against abuse using this method.
### Email Link Validity
- When working with enterprise systems, email scanners may scan and make a `GET` request to the reset password link or sign up link in your email. Since links in Supabase Auth are single use, a user who opens an email post-scan to click on a link will receive an error. To get around this problem,
consider altering the email template to replace the original magic link with a link to a domain you control. The domain can present the user with a "Sign-in" button which redirect the user to the original magic link URL when clicked.
## Next steps
This checklist is always growing so be sure to check back frequently, and also feel free to suggest additions and amendments by making a PR on [GitHub](https://github.com/supabase/supabase).