-
-
Notifications
You must be signed in to change notification settings - Fork 45
Create lockout message for mobile users #2763
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey @avazirna, Can you describe why we decided to not use existing 406 ? It seems like we are duplicating what 406 is designed to do effortlessly with a 401 here but in a more complicated fashion.
|
@damagatchi retest this please |
2 similar comments
|
@damagatchi retest this please |
|
@damagatchi retest this please |
|
@avazirna any further details on how to carry this PR forward? |
@kishansampat HQ needs to send a |
Summary
This PR presents an appropriate message to users that have been locked out of CommCare due to exceeding the maximum number of login attempts allowed. To restore the account, users need to reach out to a Supervisor or Administrator.
Note: Another design considered during this work involved receiving a
406response code from HQ and let the User Actionable errors feature handle the error message, this option was later disfavoured over a401response code with specific error messages but it can always be revisited if needed.Ticket: https://dimagi.atlassian.net/browse/SAAS-13154
Product Description
Currently, when an user is locked out, they get an

Invalid Username or Passwordmessage. With this change, the message will be:Safety Assurance
Safety story
This PR only improves error message handling on the client side, instead of having a catch-all message for all authentication failure events.