Uploaded image for project: 'mod-login'
  1. mod-login
  2. MODLOGIN-41

Backend - Security: Handling: Failed login attempts - Lock Account

    XMLWordPrintable

    Details

    • Template:
    • Sprint:
      EPAM Sprint 1, EPAM Sprint 2, EPAM Sprint 3, EPAM Sprint 4
    • Story Points:
      5
    • Development Team:
      Folijet

      Description

      As a person responsible for the security of the Folio platform
      I want to prevent brute force attacks of the Folio platform

      Conditions for Locking a Folio User Account

      • At [5] failed consecutive login attempts using a Folio username/password then lock user's Folio account
      • OR if [5] failed consecutive login attempts using Folio username/password occur in a [10 minute span] then lock user's Folio account
      • Settings Configuration: the settings in [brackets] should be configurable as Folio may need to change these settings in the future.
      • Settings Configuration: should be flexible to support additional rules for locking a user's Folio account

      Potential way to lock a Folio User Account

      • A way to lock the user's Folio account is by setting the user status = inactive

      Ways to unlock a Folio User Account

      • Via Folio, system librarian changes the user status = active

        TestRail: Results

          Attachments

            Issue Links

              Activity

                People

                Assignee:
                kgambrell Khalilah Gambrell
                Reporter:
                kgambrell Khalilah Gambrell
                Votes:
                0 Vote for this issue
                Watchers:
                5 Start watching this issue

                  Dates

                  Created:
                  Updated:
                  Resolved:

                    TestRail: Runs

                      TestRail: Cases