Rule n° 18 - Account creation is subject to a confirmation process.
To create an account on a website, it is usually necessary to enter an email address. This address can then be used to verify that the person behind the account creation request and the owner of the entered email are the same person. In the absence of such verification, anyone can create an account.
Goal
- Reduce the risk of users being registered without their knowledge.
Solution technique
Before activating the account created online, send an automatic confirmation request to the corresponding e-mail address.
Moyen de contrôle
Create an online account and check that it is only activated from the confirmation e-mail that follows the sending of the registration form.