<p></p>
<p><b>@milan-cvetkovic</b> commented on this pull request.</p>

<hr>

<p>In <a href="https://github.com/openstreetmap/openstreetmap-website/pull/4455#discussion_r1452597544">app/views/users/new_association.erb</a>:</p>
<pre style='color:#555'>> +    <h1><%= t ".title" %></h1>
+  </div>
+  <div class='header-illustration new-user-arm d-none d-md-block'></div>
+<% end %>
+
+<div class="auth-container">
+  <div class="text-muted col-sm form-container">
+
+    <h4><%= t ".welcome" %></h4>
+
+    <%= bootstrap_form_for current_user, :url => { :action => "create_association" } do |f| %>
+      <%= hidden_field_tag("referer", h(@referer)) unless @referer.nil? %>
+      <%= f.hidden_field :auth_provider %>
+      <%= f.hidden_field :auth_uid %>
+
+      <% if current_user.errors[:email].empty? %>
</pre>
<p dir="auto">Hm, interesting. I thought that it may be a good idea to verify user's password as it is known to OSM. But maybe it is a valid assumption, at least when we trust 3rd party platform about the email address.</p>
<p dir="auto">What do we do if we don't trust the email address (github, wikipedia, raw openid)? This would mean that user can create an account on github with someone elses email, then use that to login to OSM. Assuming github does not verify emails, this would allow hijacking OSM account...</p>

<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">—<br />Reply to this email directly, <a href="https://github.com/openstreetmap/openstreetmap-website/pull/4455#discussion_r1452597544">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/AAK2OLM5HDNF7IHH47NPTOTYOVNIVAVCNFSM6AAAAABBLOL2OWVHI2DSMVQWIX3LMV43YUDVNRWFEZLROVSXG5CSMV3GSZLXHMYTQMRSGAZTGOJWGU">unsubscribe</a>.<br />You are receiving this because you are subscribed to this thread.<img src="https://github.com/notifications/beacon/AAK2OLLOW2WHDBEQA5RZTHLYOVNIVA5CNFSM6AAAAABBLOL2OWWGG33NNVSW45C7OR4XAZNRKB2WY3CSMVYXKZLTORJGK5TJMV32UY3PNVWWK3TUL5UWJTTMTIEC2.gif" height="1" width="1" alt="" /><span style="color: transparent; font-size: 0; display: none; visibility: hidden; overflow: hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0; mso-hide: all">Message ID: <span><openstreetmap/openstreetmap-website/pull/4455/review/1822033965</span><span>@</span><span>github</span><span>.</span><span>com></span></span></p>
<script type="application/ld+json">[
{
"@context": "http://schema.org",
"@type": "EmailMessage",
"potentialAction": {
"@type": "ViewAction",
"target": "https://github.com/openstreetmap/openstreetmap-website/pull/4455#discussion_r1452597544",
"url": "https://github.com/openstreetmap/openstreetmap-website/pull/4455#discussion_r1452597544",
"name": "View Pull Request"
},
"description": "View this Pull Request on GitHub",
"publisher": {
"@type": "Organization",
"name": "GitHub",
"url": "https://github.com"
}
}
]</script>