Invalid User Restriction
enableFeedback) If enabled, the User Identification Step always returns a specific error code in case this restriction is violated.
If no restrictions are configured to provide feedback, a flow can also be started for users violating one or more restrictions and the flow will advance to the user identity verification step in stealth mode. In this mode, the initial behavior of the step is the same as for unrestricted users (e.g. an mTAN OTP is required), but all responses are rejected as if they were incorrect. This behavior prevents restricted users from ever proceeding further in the flow and thus offers protection against user enumeration. Please refer to the documentation for more details.
Irrespective of this settings, once the identity verification step is passed, restriction are always checked before and after each method call and violations are always reported.
Security notice: Enabling this feature might allow a client to determine whether certain users exist in the system.
type: InvalidUserRestriction
id: InvalidUserRestriction-xxxxxx
displayName:
comment:
properties:
enableFeedback: false