Skip to content

Enforce Stronger Security on Username / Password Errors #506

@jayfo

Description

@jayfo

#505 provides an appropriately ambiguous "Username or password incorrect." error.

But the underlying error messages from Cognito are not similarly ambiguous. Cognito has updated with a capability to not provide any error message that would reveal an account. We should enable that and then review handling of error scenarios.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions