What information we return on unsuccessful attempt to login
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 92
- Forks
- 81
- Avg merge
- 1d 9h
- Merged PRs (30d)
- 46
Description
Is your feature request related to a problem? Please describe.
As a squad we have different understanding of what is insecure with respect to the information returned on unsuccessfully attempts to login and what mechanisms needs to be introduced. As this discussion is tradeoff between user experience and security we need to find an agreement and then continue based on this shared agreement.
Describe the solution you'd like
Policy that will become part of the API Mediation Layer repository, which outlines our approach towards the information that are returned.
Describe alternatives you've considered
Having TSC level policy, but this takes far more time and it's more difficult to agree across all the squads with different levels of criticality.
Willingness to help
I am volunteering @JirkaAichler , @pj892031 as they are mostly involved and invested in the issues that are coming from varied understanding across the squad.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the proposed repository policy for information returned after unsuccessful login attempts and review the existing API Mediation Layer guidance relevant to authentication responses. The work is done when the squad agrees on the security and user-experience approach and that policy is added to the repository.
Written by the indexing model from the issue text.
Assessment
- Domain
- api, documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100