Looks like the future might hold OAuth, according to discussions with @pwalsh. A sensible first step towards making SpenDB into an OAuth consumer would be to rip user names out of the app, and use IDs instead for profile pages and the account API. People can still log in using their email, and we can later switch that to OAuth which doesn't reliably provide user names.
Looks like the future might hold OAuth, according to discussions with @pwalsh. A sensible first step towards making SpenDB into an OAuth consumer would be to rip user names out of the app, and use IDs instead for profile pages and the account API. People can still log in using their email, and we can later switch that to OAuth which doesn't reliably provide user names.