Need to consider account status in authentication process
Closed this issue · 0 comments
longrunningprocess commented
authentication should not pass when an account is either inactive or locked, even if the password is correct.
Also important to take into account timing attack prevention.