You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I have enabled Brut Force detection and it works fine.
However, telling the person that the account they are trying to access is blocked gives them the information that the account exists, which is important information in the event of a fraudulent access attempt.
Is it possible to add options for:
have the same answer when the account is blocked as when the password is incorrect or an account does not exist (do not have error_code=account_locked)
send an email to the user to let him know that his account is blocked with, why not, a link to unblock it).
Thank you.
The text was updated successfully, but these errors were encountered:
tcompiegne
changed the title
[AM] email when the account is blocked
[gateway] send en email when the account is blocked
Sep 13, 2019
I have enabled Brut Force detection and it works fine.
However, telling the person that the account they are trying to access is blocked gives them the information that the account exists, which is important information in the event of a fraudulent access attempt.
Is it possible to add options for:
Thank you.
The text was updated successfully, but these errors were encountered: