Replies: 2 comments
-
@ndegwamartin @pld Keycloak already allows this we just need to decide on how the application and web app behave after the account is locked.
|
Beta Was this translation helpful? Give feedback.
0 replies
-
Cool so 2 options then
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Describe the issue to be researched
PATH have made a request for the ability to lock out the app users who input the wrong password for a specified number of times. The lock-out would be for a specified amount of time before they can retry login or contact an admin where they are totally unable login.
A possible approach would be through key-cloak but this would need the device to be online. This feature is sought to be resident on the app and to work even when the users have no internet connection.
What would it take to achieve this request on OpenSRP 2?
Describe the goal of the research
This is as a security measure that is meant to lock anyone who may be trying to impersonate a user or not a valid system user.
Describe the methodology
This request is at exploration level to determine what is presently possible.
Beta Was this translation helpful? Give feedback.
All reactions