Content
View differences
Updated by Max Mutzge about 5 years ago
To avoid confusion, improve the user experience and reduce the workload for support (only small effect) <mention class="mention" data-id="3762" data-type="user" data-text="@Robin Wagner">@Robin Wagner</mention> and I propose the following changes:
Current situation: Basically, there are three cases (from a user's perspective):
* user forgot his/her password
* user forgot or misspelled his/her password and gets blocked temporarily
* user has been locked permanently by an admin
The current situation and the "process" can be found in this overview, as well as the proposed solution (**desired (desired changes marked with dotted box in the lower display**): display):
<figure class="image op-uc-figure" style="width:75%;"><div class="op-uc-figure--content"><img class="op-uc-image" src="/api/v3/attachments/20830/content"></div></figure>
**Acceptance criteria**
_("Optional" points can be dropped if the implementation effort would exceed the benefits)_
* Change error message for wrong password and for temporary block to:
_"Invalid "Invalid username or password._ password.
_For If your credentials are correct, your account may have been blocked due to multiple failed login attempts. If so, it will be unblocked automatically in a short time.
For questions please contact your administrator."_ administrator."
* Optional: Add link to the password reset screen, like so: _"Invalid "Invalid username or password. \[Click here if you forgot your password.\]_ password.\] <br> _If ..."_ If ..."
* Optional: Change error message for permanently locked users to:
_"Your "Your account has been locked by an administrator._ administrator.
_For For questions please contact your administrator."_ administrator."
* Optional: Unify behavior of the application after having entered an email address for password reset: Redirect to sign in page also for non-existing (i.e. unknown) email addresses
* When a user who has been permanently locked tries to reset his/her password send this email instead of the password reset email:
"Your account has been permanently locked. For questions please contact your administrator"
* Optional: Option for administrators to enter some form of contact details for contacting the admin
* When a user who has been blocked temporarily resets his/her password he/she should be able to log in with the new password (currently user the block is not lifted when resetting the password)
### Current situation
<figure class="image op-uc-figure"><div class="op-uc-figure--content"><img class="op-uc-image" src="/api/v3/attachments/20367/content"></div></figure>
Current situation: Basically, there are three cases (from a user's perspective):
* user forgot his/her password
* user forgot or misspelled his/her password and gets blocked temporarily
* user has been locked permanently by an admin
The current situation and the "process" can be found in this overview, as well as the proposed solution (**desired
<figure class="image op-uc-figure" style="width:75%;"><div class="op-uc-figure--content"><img class="op-uc-image" src="/api/v3/attachments/20830/content"></div></figure>
_("Optional" points can be dropped if the implementation effort would exceed the benefits)_
_"Invalid
_For
For
* Optional: Add link to the password reset screen, like so: _"Invalid
* Optional: Change error message for permanently locked users to:
_"Your
_For
* Optional: Unify behavior of the application after having entered an email address for password reset: Redirect to sign in page also for non-existing (i.e. unknown) email addresses
* When a user who has been permanently locked tries to reset his/her password send this email instead of the password reset email:
"Your account has been permanently locked. For questions please contact your administrator"
* Optional: Option for administrators to enter some form of contact details for contacting the admin
* When a user who has been blocked temporarily resets his/her password he/she should be able to log in with the new password (currently user the block is not lifted when resetting the password)
<figure class="image op-uc-figure"><div class="op-uc-figure--content"><img class="op-uc-image" src="/api/v3/attachments/20367/content"></div></figure>