zowe / zowe/api-layer

What information we return on unsuccessful attempt to login

Open
#3,243 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

architecture enhancement Priority: High size/L
Dominant language
Java
Stars
92
Forks
81
Avg merge
1d 9h
Merged PRs (30d)
46

Description

Is your feature request related to a problem? Please describe.
As a squad we have different understanding of what is insecure with respect to the information returned on unsuccessfully attempts to login and what mechanisms needs to be introduced. As this discussion is tradeoff between user experience and security we need to find an agreement and then continue based on this shared agreement.

Describe the solution you'd like
Policy that will become part of the API Mediation Layer repository, which outlines our approach towards the information that are returned.

Describe alternatives you've considered
Having TSC level policy, but this takes far more time and it's more difficult to agree across all the squads with different levels of criticality.

Willingness to help
I am volunteering @JirkaAichler , @pj892031 as they are mostly involved and invested in the issues that are coming from varied understanding across the squad.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the proposed repository policy for information returned after unsuccessful login attempts and review the existing API Mediation Layer guidance relevant to authentication responses. The work is done when the squad agrees on the security and user-experience approach and that policy is added to the repository.

Written by the indexing model from the issue text.

Assessment

Domain
api, documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.