From d63e60e7d7b2dfe5e460b476c8fedf3bbcad360b Mon Sep 17 00:00:00 2001 From: Joel Lee Date: Mon, 6 Jun 2022 11:33:14 +0800 Subject: [PATCH] Update web/docs/guides/auth/auth-twilio.mdx --- web/docs/guides/auth/auth-twilio.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/web/docs/guides/auth/auth-twilio.mdx b/web/docs/guides/auth/auth-twilio.mdx index 66e00a49d0f..ed4c19deea5 100644 --- a/web/docs/guides/auth/auth-twilio.mdx +++ b/web/docs/guides/auth/auth-twilio.mdx @@ -93,7 +93,7 @@ Use the variable `.Code` in the template to display the OTP code. Here's an ![ex ### Using OTP with password based logins -In this scenario we'll be using the user's mobile phone number and a corrsesponding password as an alternative to signing up with an email address. Note: Please deeply consider the potential security implications when signing up with a combination ofphone and passsword. It is not uncommon for mobile phone numbers to be recycled by phone networks when users cancel their phone contracts or move countries, therefore granting access to the user's account to the subsequent owner of the phone number. In the near future Supabase will support multifactor auth, which will mitigate this risk, but for now you may want to consider allowing your users to recover their account by some other means in an emergency. +In this scenario we'll be using the user's mobile phone number and a corresponding password as an alternative to signing up with an email address. Note: Please deeply consider the potential security implications when signing up with a combination ofphone and passsword. It is not uncommon for mobile phone numbers to be recycled by phone networks when users cancel their phone contracts or move countries, therefore granting access to the user's account to the subsequent owner of the phone number. In the near future Supabase will support multifactor auth, which will mitigate this risk, but for now you may want to consider allowing your users to recover their account by some other means in an emergency. Using supabase-js on the client you'll want to use the same `signUp` method that you'd use for email based sign ups, but with the `phone` param instead of the `email param`: