Content
View differences
Updated by Robin Wagner over 5 years ago
**As** an OpenProject user
**I want to** get an error message which doesn't tell me "your account is locked" or "you tried a wrong username/password multiple times" although this is not true when I enter a wrong username or password
**so that** I don't get confused.
**Acceptance criteria**
* Split error message in two cases:
* Change error message for failed login attempt: "Invalid user name or password entered. Please try again or use the link 'Forgot your password?'"
**To be discussed**
* If possible, link text "Forgot your password?" to Should the password reset screen (/account/lost\_password)
* Additional error message when the user is blocked: "User account two cases ("wrong username/password" and "account locked temporarily due to multiple failed login attempts. It will faulty insertions") be unlocked automatically in a short time. Alternatively, please contact your admin differentiated and lead to be unlocked."
**To be discussed**
* Verify that these two cases do not pose an additional security risk. different behaviors (e.g. different error messages)?
### Current situation
<figure class="image op-uc-figure"><div class="op-uc-figure--content"><img class="op-uc-image" src="/api/v3/attachments/20367/content"></div></figure>
**I want to** get an error message which doesn't tell me "your account is locked" or "you tried a wrong username/password multiple times" although this is not true when I enter a wrong username or password
**so that** I don't get confused.
**Acceptance criteria**
* Split error message in two cases:
* Change error message for failed login attempt: "Invalid user name or password entered. Please try again or use the link 'Forgot your password?'"
**To be discussed**
* Additional error message when the user is blocked: "User account
**To be discussed**
* Verify that these two cases do not pose an additional security risk.
### Current situation
<figure class="image op-uc-figure"><div class="op-uc-figure--content"><img class="op-uc-image" src="/api/v3/attachments/20367/content"></div></figure>