Default Self-Unlock Restrictions
Default restrictions for self-unlock flows. Currently, they are (in this order):
- Nonexistent User Restriction
- Invalid User Restriction
- Locked User Restriction (only users with one of the configured "Allowed Lock Reasons" are allowed to perform self-unlock. Users that are not locked may still perform a self-unlock flow.)
- Too Many Unlocks Restriction
By default, these restrictions do not report violations and therefore prevent user enumeration. To include custom restrictions or to configure restrictions for other types of self-service flows, the "Custom Public Self-Service Restrictions" plugin can be used.
nonexistentUserFeedback) If enabled, nonexistent users attempting to start a self-unlock flow receive an error response with error code "USER_NOT_FOUND". Otherwise, the flow would also continue for nonexistent users but fail in the verification step (to protect against user enumeration).
Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.
invalidUserFeedback) If enabled, invalid users attempting to start a self-unlock flow receive an error response with error code "USER_INVALID". Otherwise, the flow would also continue for invalid users, but fail in the verification step (to protect against user enumeration).
Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.
lockedUserFeedback) If enabled, locked users attempting to start a self-unlock flow receive an error response with error code "USER_LOCKED". Otherwise, the flow would also continue for locked users but fail in the verification step (to protect against user enumeration).
Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.
tooManyUnlockFeedback) If enabled and the 'Public Self-Service Flow Settings' configuration has a 'Max Number of Unlocks' limit configured, locked users with more unlock attempts attempting to start a self-unlock flow receive an error response with error code "TOO_MANY_UNLOCKS". Otherwise, the flow would also continue for locked users but fail in the verification step (to protect against user enumeration).
Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.
allowedLockReasons) List of lock reasons that still allow the user to perform the self-unlock. Locked users with any lock reason not listed here will be rejected.
Note that a user is not automatically unlocked after a successful public self-service. A "Unlock User Step (Public Self-Service)" step has to be configured to perform this task.
type: DefaultSelfUnlockRestrictions
id: DefaultSelfUnlockRestrictions-xxxxxx
displayName:
comment:
properties:
allowedLockReasons: [LockReason.TooManyAuthAtts.PASSWORD]
invalidUserFeedback: false
lockedUserFeedback: false
nonexistentUserFeedback: false
tooManyUnlockFeedback: false