Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Challenge question settings #623

Open
ph1403 opened this issue Sep 9, 2021 · 0 comments
Open

Challenge question settings #623

ph1403 opened this issue Sep 9, 2021 · 0 comments

Comments

@ph1403
Copy link
Contributor

ph1403 commented Sep 9, 2021

I would like to suggest a setting either globally with admin defined questions or on a question by question basis so that we can bypass the text.contains() validation [https://github.com/pwm-project/pwm/blob/7c849c94b7f91168c9a6afc250e14c9c6b57717b/server/src/main/java/password/pwm/svc/cr/NMASCrOperator.java#L537].

I would also like to suggest allowing for challenge questions to be bit more modular such that they could be required for Help Desk questions without the need for self-service reset questions. I find clients often like the help desk ones for ID Proofing, but don't like security questions for password reset.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants