Disabled Or Missing Secret Questions Restriction
Description
Does not allow users that cannot use secret questions to perform a public self-service and returns a corresponding feedback message. A user must have enough secret questions provisioned and they must be active for this user.
For public self-service flows using secret question identity verification, the purpose of this restriction is only to add an informative feedback message. This increases usability but could allow user enumeration since it makes it possible to find existing users without secret questions.
We recommend to configure this restriction as the last restriction to be checked.
May be used by
Properties
Secret Questions Settings (
secretQuestionsSettings) Description
Settings related to secret questions.
Attributes
Plugin-Link
Mandatory
Assignable plugins
YAML Template (with default values)
type: DisabledOrMissingSecretQuestionsRestriction
id: DisabledOrMissingSecretQuestionsRestriction-xxxxxx
displayName:
comment:
properties:
secretQuestionsSettings: