Patterns
Email verification before privileged actions
Don’t let unverified accounts pay, invite teammates, or perform destructive actions.
Lock accounts after repeated failures
5 wrong passwords in 15 minutes → temporary lock. Built into vly’s auth flow.
Require MFA for admins
Workspace owners and admins should enable TOTP. Enforce with a setting.
Short session lifetime for sensitive surfaces
Reduce session TTL for billing pages; require re-auth before destructive actions.
Never email passwords
For password reset, send a one-time link, not the password itself.
Sanitize user-provided redirect URLs
“Sign in then return to ?redirect=…” — only allow same-origin redirects.
Don’t
Don't store passwords in plain text
Don't store passwords in plain text
vly’s built-in auth never does this; if you implement custom auth, use bcrypt / Argon2.
Don't roll your own JWT library
Don't roll your own JWT library
Use vly’s session model. Custom JWT implementations have notorious foot-guns (none algorithm, key confusion, etc.).
Don't reveal whether an email is registered
Don't reveal whether an email is registered
“No account with that email” leaks info to attackers. Either say “If an account exists, we sent a link” or accept the small UX hit for the security gain.
Related
Built-in auth
The auth system.
Rate limiting
Defend auth endpoints.
Auth flows
Patterns for common scenarios.
