Best practices for login pages?

前端 未结 12 1959
后悔当初
后悔当初 2021-01-31 19:30

I am working on a single sign-on login page using Shibboleth that will be used for a variety of web applications. Obviously we would like to make this page as secure and usable

12条回答
  •  攒了一身酷
    2021-01-31 20:17

    One other "no duh" thing that I still see on a lot of applications I go to, if the credentials specified are invalid, do not indicate which one is invalid. Simply say something like "invalid user/password combination" instead of "invalid password" that will prevent those folks from social engineering to know a user base accessing your site.

提交回复
热议问题