Locked User Restriction
allowedLockReasons) List of lock reasons that still allow the user to perform public self-services. Locked users with any lock reason not listed here will not be allowed to perform public self-services.
Note that a user is not automatically unlocked after a successful public self-service. A "Unlock User Step (Public Self-Service)" step has to be configured to perform this task.
enableFeedback) If enabled, the User Identification Step always returns a specific error code in case this restriction is violated.
If no restrictions are configured to provide feedback, a flow can also be started for users violating one or more restrictions and the flow will advance to the user identity verification step in stealth mode. In this mode, the initial behavior of the step is the same as for unrestricted users (e.g. an mTAN OTP is required), but all responses are rejected as if they were incorrect. This behavior prevents restricted users from ever proceeding further in the flow and thus offers protection against user enumeration. Please refer to the documentation for more details.
Irrespective of this settings, once the identity verification step is passed, restriction are always checked before and after each method call and violations are always reported.
Security notice: Enabling this feature might allow a client to determine whether certain users exist in the system.
type: LockedUserRestriction
id: LockedUserRestriction-xxxxxx
displayName:
comment:
properties:
allowedLockReasons:
enableFeedback: false