● Company Code Entry and CAPTCHA Integration:
○ Description: Users must enter a valid company code and complete a CAPTCHA
challenge to initiate the login process.
○ Business Rules & Validations:
■ Required Fields: Both the company code and CAPTCHA fields are
mandatory.
■ Company Code Validation: The system verifies the entered company
code against the database to ensure its validity.
■ CAPTCHA Validation: Users must successfully complete the CAPTCHA
challenge to proceed.
■ Error Handling:
■ If an invalid company code is entered, an error message is
displayed prompting the user to re-enter a valid code.
■ If the CAPTCHA validation fails, the user is prompted to retry the
CAPTCHA.
■ Button Label: After entering the company code and completing the
CAPTCHA, the button label changes from “Verify” to “Proceed”.
● User Authentication:
○ Description: After successful company code verification and CAPTCHA
completion, users provide their email and password to log in.
○ Business Rules & Validations:
■ Required Fields: Both email and password fields are mandatory.
■ Email Validation: The email must follow a valid email format (e.g.,
user@example.com).
■ Password Validation: Passwords must meet complexity requirements
(e.g., minimum length, inclusion of special characters).
■ Error Handling: If the email or password is incorrect, an appropriate error
message is displayed.
■ Session Management: Upon successful authentication, a user session is
created and managed securely.
● Microsoft Login:
○ Description: Console users added under the Teammates module can log in
using their Microsoft accounts by clicking the “Sign In with Microsoft” button.
○ Business Rules & Validations:
■ Eligibility: Only users who are part of the Teammates module and have
been granted access can use Microsoft Login.
■ Policy Compliance: The company must configure and allow specific
Microsoft policies to enable this login method.
■ Error Handling:
■ If Microsoft Login fails due to policy restrictions or authentication
errors, users receive an error message with instructions to contact
support.
■ Integration: Microsoft Login integrates with OAuth 2.0 for secure
authentication.
● CAPTCHA Integration:
○ Description: A CAPTCHA challenge is presented to users to prevent automated
login attempts.
○ Business Rules & Validations:
■ Configurability: CAPTCHA can be enabled or disabled based on
environment settings (e.g., production, staging).
■ Required Field: When enabled, completing the CAPTCHA is mandatory
for login.
■ Error Handling: If the CAPTCHA validation fails, the user is prompted to
retry.
● Rate Limiting:
○ Description: Implements rate limiting to prevent brute-force attacks by restricting
the number of failed login attempts within a specific time frame.
○ Business Rules & Validations:
■ Time Window: 900 seconds (15 minutes).
■ Thresholds:
■ Per User: Maximum of 5 failed login attempts.
■ Per IP Address: Maximum of 15 failed login attempts.
■ Global: Maximum of 50 failed login attempts across all users and
IPs.
■ Block Actions:
■ User Block: If a user exceeds 5 failed attempts within 15 minutes,
further login attempts for that user are blocked for 15 minutes.
■ IP Block: If an IP address exceeds 15 failed attempts within 15
minutes, further login attempts from that IP are blocked for 15
minutes.
■ Global Block: If the system detects 50 failed attempts within 15
minutes globally, all login attempts are temporarily blocked for 15
minutes.
■ Error Handling:
■ When a block is triggered, users receive an error message
indicating that their login attempts have been temporarily blocked
due to too many failed attempts.
■ Instructions are provided on how to proceed, such as waiting for
the block to lift or contacting support if necessary.
■ Block Duration: All blocks (user, IP, and global) last for 900 seconds (15
minutes) before they are automatically lifted.
Functional Specifications
Updated on August 11, 2025
devdocs