Module Breakdown

  • 3.1 Login
    • 3.1.1 Module Overview
      • The Login module enables console users to securely access the talkk.ai platform.
      • It manages the authentication process by verifying company codes, validating user credentials, and handling user sessions.
      • The module integrates CAPTCHA functionality alongside company code verification to enhance security, which can be configured based on the deployment environment.
      • It supports Microsoft Login for users added under the Teammates module, allowing them to authenticate using their Microsoft accounts.
      • The module implements rate limiting to prevent brute-force attacks by restricting the number of failed login attempts within a specified time frame.
    • 3.1.2 Functional Specifications
      • Company Code Entry and CAPTCHA Integration
        • Description: Users must enter a valid company code and complete a CAPTCHA challenge to initiate the login process.
        • Business Rules & Validations:
          • Required Fields: Both the company code and CAPTCHA fields are mandatory.
          • Company Code Validation: The system verifies the entered company code against the database to ensure its validity.
          • CAPTCHA Validation: Users must successfully complete the CAPTCHA challenge to proceed.
          • Error Handling:
            • If an invalid company code is entered, an error message is displayed prompting the user to re-enter a valid code.
            • If the CAPTCHA validation fails, the user is prompted to retry the CAPTCHA.
          • Button Label: After entering the company code and completing the CAPTCHA, the button label changes from “Verify” to “Proceed”.
      • User Authentication
        • Description: After successful company code verification and CAPTCHA completion, users provide their email and password to log in.
        • Business Rules & Validations:
          • Required Fields: Both email and password fields are mandatory.
          • Email Validation: The email must follow a valid email format (e.g., user@example.com).
          • Password Validation: Passwords must meet complexity requirements (e.g., minimum length, inclusion of special characters).
          • Error Handling: If the email or password is incorrect, an appropriate error message is displayed.
          • Session Management: Upon successful authentication, a user session is created and managed securely.
      • Microsoft Login
        • Description: Console users added under the Teammates module can log in using their Microsoft accounts by clicking the “Sign In with Microsoft” button.
        • Business Rules & Validations:
          • Eligibility: Only users who are part of the Teammates module and have been granted access can use Microsoft Login.
          • Policy Compliance: The company must configure and allow specific Microsoft policies to enable this login method.
          • Error Handling:
            • If Microsoft Login fails due to policy restrictions or authentication errors, users receive an error message with instructions to contact support.
          • Integration: Microsoft Login integrates with OAuth 2.0 for secure authentication.
      • CAPTCHA Integration
        • Description: A CAPTCHA challenge is presented to users to prevent automated login attempts.
        • Business Rules & Validations:
          • Configurability: CAPTCHA can be enabled or disabled based on environment settings (e.g., production, staging).
          • Required Field: When enabled, completing the CAPTCHA is mandatory for login.
          • Error Handling: If the CAPTCHA validation fails, the user is prompted to retry.
      • Rate Limiting
        • Description: Implements rate limiting to prevent brute-force attacks by restricting the number of failed login attempts within a specific time frame.
        • Business Rules & Validations:
          • Time Window: 900 seconds (15 minutes).
          • Thresholds:
            • Per User: Maximum of 5 failed login attempts.
            • Per IP Address: Maximum of 15 failed login attempts.
            • Global: Maximum of 50 failed login attempts across all users and IPs.
          • Block Actions:
            • User Block: If a user exceeds 5 failed attempts within 15 minutes, further login attempts for that user are blocked for 15 minutes.
            • IP Block: If an IP address exceeds 15 failed attempts within 15 minutes, further login attempts from that IP are blocked for 15 minutes.
            • Global Block: If the system detects 50 failed attempts within 15 minutes globally, all login attempts are temporarily blocked for 15 minutes.
          • Error Handling:
            • When a block is triggered, users receive an error message indicating that their login attempts have been temporarily blocked due to too many failed attempts.
            • Instructions are provided on how to proceed, such as waiting for the block to lift or contacting support if necessary.
          • Block Duration: All blocks (user, IP, and global) last for 900 seconds (15 minutes) before they are automatically lifted.
    • 3.1.3 Operational Details
      • Usage Instructions:
        • Accessing the Login Page:
          • Navigate to the talkk.ai console login URL.
        • Logging In:
          • Standard Login:
            • Enter the Company Code and complete the CAPTCHA challenge.
            • Click the “Proceed” button.
            • If the company code is valid and CAPTCHA is successfully completed, enter your Email and Password.
            • Click “Login” to access the console.
          • Microsoft Login:
            • Click the “Sign In with Microsoft” button.
            • You will be redirected to the Microsoft authentication page.
            • Enter your Microsoft account credentials.
            • If authentication is successful and policies are compliant, you will be logged into the talkk.ai console.
    • 3.1.4 Common Issues and Troubleshooting
      • Issue: Invalid Company Code
        • Description: Users receive an error indicating the entered company code is invalid.
        • Resolution:
          • Verify that the company code entered is correct.
          • Ensure the company code exists in the system.
          • Contact support if the issue persists.
      • Issue: Incorrect Email or Password
        • Description: Users are unable to log in due to incorrect credentials.
        • Resolution:
          • Confirm that the email and password entered are correct.
          • Use the password recovery feature if the password is forgotten.
          • Check for any account lockout due to multiple failed attempts.
      • Issue: CAPTCHA Not Loading or Failing
        • Description: The CAPTCHA challenge does not appear or fails to validate.
        • Resolution:
          • Verify CAPTCHA service configuration and ensure the secret key is correctly set in environment variables.
          • Check network connectivity and service status of the CAPTCHA provider.
          • Review logs for any errors related to CAPTCHA integration.
      • Issue: Login Blocked Due to Too Many Failed Attempts
        • Description: Users are temporarily blocked from logging in after exceeding the allowed number of failed attempts.
        • Resolution:
          • For User Blocks:
            • Wait for the 15-minute time window to reset.
            • Ensure correct credentials are used in subsequent attempts.
            • Contact support if the block persists beyond the expected duration.
          • For IP Blocks:
            • Verify that the IP address is not being used maliciously.
            • Wait for the 15-minute time window to reset.
            • Consider using a different network if the IP block affects legitimate users.
          • For Global Blocks:
            • Recognize that the system has detected a high volume of failed login attempts.
            • Wait for the 15-minute time window to reset.
            • If global blocks occur frequently, investigate potential security threats or system issues.
          • General Resolution Steps:
            • Clear browser cache and cookies.
            • Ensure that automated scripts or bots are not attempting multiple logins.
            • Monitor login attempts to identify and mitigate malicious activities.
      • Issue: Microsoft Login Failure
        • Description: Users are unable to log in using their Microsoft accounts.
        • Resolution:
          • Ensure that the user’s Microsoft account is correctly added under the Teammates module.
          • Verify that the company has configured and allowed the necessary Microsoft policies for authentication.
          • Check the integration settings and OAuth 2.0 configurations.
          • Contact support if the issue persists after verifying the above steps.

In Module Breakdown

Next

Leave a Reply

Your email address will not be published. Required fields are marked *