← Back to plugin index

User Enumeration Protection Processor

Description

Processor that protects against user enumeration attacks by changing any failure of a user identifying step to a generic AUTHENTICATION_FAILED result.

To ensure that all failed results are made generic, this processor must be configured after the "Default Authentication Processor" and the "User Validity Processor".

Type name
UserEnumerationProtectionProcessor
Class
com.airlock.iam.authentication.application.configuration.processor.UserEnumerationProtectionProcessorConfig
May be used by
Properties
YAML Template (with default values)

type: UserEnumerationProtectionProcessor
id: UserEnumerationProtectionProcessor-xxxxxx
displayName: 
comment: 
properties: