Currently the token (subscription) is confirmed simply by visiting the confirmation URL the subscriber found in their email. We should require an additional user action (a button click) to help prevent accidental confirmations as well as to prevent accidental automated confirmations if an email spam prevention measure hits URLs in emails looking for dead or harmful links or redirects.
Thanks pmac. I'll add this to the backlog of ideas to explore and potentially implement post our CRM integration work.
Duplicate of this bug: 1271414
If you do add a button please please please add an anti-csrf token so it can't be spammed.
Although short of something like a captcha that won't stop scripted spam attacks.
