Uploaded image for project: 'RH-SSO'
  1. RH-SSO
  2. RHSSO-342

Error message on login after being blocked by brute-force

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • RH-SSO-7.0.0.GA
    • None
    • Server
    • None

      When being on login page and trying to login into the realm with strict brute-force settings user might end up trying to enter some of his/her credentials and getting the error 'Invalid username or password.' while error is in fact 'user_temporarily_disabled'.
      User should see this error as soon as he's blocked, or this message should at least be configurable. Otherwise it may be very confusing for the innocent user in some circumstances.

            Unassigned Unassigned
            irum@redhat.com Alice Rum (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: