- 3.1 Login
- 3.1.1 Module Overview
- The Login module enables console users to securely access the talkk.ai platform.
- It manages the authentication process by verifying company codes, validating user credentials, and handling user sessions.
- The module integrates CAPTCHA functionality alongside company code verification to enhance security, which can be configured based on the deployment environment.
- It supports Microsoft Login for users added under the Teammates module, allowing them to authenticate using their Microsoft accounts.
- The module implements rate limiting to prevent brute-force attacks by restricting the number of failed login attempts within a specified time frame.
- 3.1.2 Functional Specifications
- Company Code Entry and CAPTCHA Integration
- Description: Users must enter a valid company code and complete a CAPTCHA challenge to initiate the login process.
- Business Rules & Validations:
- Required Fields: Both the company code and CAPTCHA fields are mandatory.
- Company Code Validation: The system verifies the entered company code against the database to ensure its validity.
- CAPTCHA Validation: Users must successfully complete the CAPTCHA challenge to proceed.
- Error Handling:
- If an invalid company code is entered, an error message is displayed prompting the user to re-enter a valid code.
- If the CAPTCHA validation fails, the user is prompted to retry the CAPTCHA.
- Button Label: After entering the company code and completing the CAPTCHA, the button label changes from “Verify” to “Proceed”.
- User Authentication
- Description: After successful company code verification and CAPTCHA completion, users provide their email and password to log in.
- Business Rules & Validations:
- Required Fields: Both email and password fields are mandatory.
- Email Validation: The email must follow a valid email format (e.g., user@example.com).
- Password Validation: Passwords must meet complexity requirements (e.g., minimum length, inclusion of special characters).
- Error Handling: If the email or password is incorrect, an appropriate error message is displayed.
- Session Management: Upon successful authentication, a user session is created and managed securely.
- Microsoft Login
- Description: Console users added under the Teammates module can log in using their Microsoft accounts by clicking the “Sign In with Microsoft” button.
- Business Rules & Validations:
- Eligibility: Only users who are part of the Teammates module and have been granted access can use Microsoft Login.
- Policy Compliance: The company must configure and allow specific Microsoft policies to enable this login method.
- Error Handling:
- If Microsoft Login fails due to policy restrictions or authentication errors, users receive an error message with instructions to contact support.
- Integration: Microsoft Login integrates with OAuth 2.0 for secure authentication.
- CAPTCHA Integration
- Description: A CAPTCHA challenge is presented to users to prevent automated login attempts.
- Business Rules & Validations:
- Configurability: CAPTCHA can be enabled or disabled based on environment settings (e.g., production, staging).
- Required Field: When enabled, completing the CAPTCHA is mandatory for login.
- Error Handling: If the CAPTCHA validation fails, the user is prompted to retry.
- Rate Limiting
- Description: Implements rate limiting to prevent brute-force attacks by restricting the number of failed login attempts within a specific time frame.
- Business Rules & Validations:
- Time Window: 900 seconds (15 minutes).
- Thresholds:
- Per User: Maximum of 5 failed login attempts.
- Per IP Address: Maximum of 15 failed login attempts.
- Global: Maximum of 50 failed login attempts across all users and IPs.
- Block Actions:
- User Block: If a user exceeds 5 failed attempts within 15 minutes, further login attempts for that user are blocked for 15 minutes.
- IP Block: If an IP address exceeds 15 failed attempts within 15 minutes, further login attempts from that IP are blocked for 15 minutes.
- Global Block: If the system detects 50 failed attempts within 15 minutes globally, all login attempts are temporarily blocked for 15 minutes.
- Error Handling:
- When a block is triggered, users receive an error message indicating that their login attempts have been temporarily blocked due to too many failed attempts.
- Instructions are provided on how to proceed, such as waiting for the block to lift or contacting support if necessary.
- Block Duration: All blocks (user, IP, and global) last for 900 seconds (15 minutes) before they are automatically lifted.
- Company Code Entry and CAPTCHA Integration
- 3.1.3 Operational Details
- Usage Instructions:
- Accessing the Login Page:
- Navigate to the talkk.ai console login URL.
- Logging In:
- Standard Login:
- Enter the Company Code and complete the CAPTCHA challenge.
- Click the “Proceed” button.
- If the company code is valid and CAPTCHA is successfully completed, enter your Email and Password.
- Click “Login” to access the console.
- Microsoft Login:
- Click the “Sign In with Microsoft” button.
- You will be redirected to the Microsoft authentication page.
- Enter your Microsoft account credentials.
- If authentication is successful and policies are compliant, you will be logged into the talkk.ai console.
- Standard Login:
- Accessing the Login Page:
- Usage Instructions:
- 3.1.4 Common Issues and Troubleshooting
- Issue: Invalid Company Code
- Description: Users receive an error indicating the entered company code is invalid.
- Resolution:
- Verify that the company code entered is correct.
- Ensure the company code exists in the system.
- Contact support if the issue persists.
- Issue: Incorrect Email or Password
- Description: Users are unable to log in due to incorrect credentials.
- Resolution:
- Confirm that the email and password entered are correct.
- Use the password recovery feature if the password is forgotten.
- Check for any account lockout due to multiple failed attempts.
- Issue: CAPTCHA Not Loading or Failing
- Description: The CAPTCHA challenge does not appear or fails to validate.
- Resolution:
- Verify CAPTCHA service configuration and ensure the secret key is correctly set in environment variables.
- Check network connectivity and service status of the CAPTCHA provider.
- Review logs for any errors related to CAPTCHA integration.
- Issue: Login Blocked Due to Too Many Failed Attempts
- Description: Users are temporarily blocked from logging in after exceeding the allowed number of failed attempts.
- Resolution:
- For User Blocks:
- Wait for the 15-minute time window to reset.
- Ensure correct credentials are used in subsequent attempts.
- Contact support if the block persists beyond the expected duration.
- For IP Blocks:
- Verify that the IP address is not being used maliciously.
- Wait for the 15-minute time window to reset.
- Consider using a different network if the IP block affects legitimate users.
- For Global Blocks:
- Recognize that the system has detected a high volume of failed login attempts.
- Wait for the 15-minute time window to reset.
- If global blocks occur frequently, investigate potential security threats or system issues.
- General Resolution Steps:
- Clear browser cache and cookies.
- Ensure that automated scripts or bots are not attempting multiple logins.
- Monitor login attempts to identify and mitigate malicious activities.
- For User Blocks:
- Issue: Microsoft Login Failure
- Description: Users are unable to log in using their Microsoft accounts.
- Resolution:
- Ensure that the user’s Microsoft account is correctly added under the Teammates module.
- Verify that the company has configured and allowed the necessary Microsoft policies for authentication.
- Check the integration settings and OAuth 2.0 configurations.
- Contact support if the issue persists after verifying the above steps.
- Issue: Invalid Company Code
- 3.1.1 Module Overview
Module Breakdown
Updated on August 26, 2025
devdocs