A system that could work but that wouldn't need the use of the users password could be something like this (This wouldn't be able to create a new thread by email)
A user signs up to recieve replies to a thread/forum. They get a reply to the thread which also contains a thread unique identifier for them and that thread (maybe even that reply) if they then reply to that email that text is posted after the unique identifier and thier email have been checked.
So if a user has the thread unique identifier stolen/abused it can only be used to reply to that one thread and can't be used to login to the forums. Without it all emails are ignored.
|