-
Type:
Change Request
-
Status: Closed
-
Priority:
High
-
Resolution: Done
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: TSR
-
Labels:None
-
Module:Platform - Security
-
Reported by:Client
-
Item State:Production Complete - Closed
-
Sprint:TSR OnBoard - 28 Mar - 12 May
-
Severity:Simple
-
Dev Estimates:16
-
Code Reviewed By:Saurabh Sablaka
Problem Statement:
Workterra allows only unique username in system under a particular company. This username generation is driven on basis of ‘Security’ customization. Consider username policy specified as email address [Everything in-front of @ symbol in the email address will be considered as userid ].
System has an existing employee “Name : Jack Smith, Email: Jack.Smith@gmail.com, Username: jack.smith”,
now a new employee record is added with following details – “Name : Jack Smith, Email: Jack.Smith@yahoo.com”. At this point system by default appends a random unique numerical extension to this employee’s username such that username for this employee will be “jack.smith4321”.
The notification email sent to employee contains only credentials policy as below –
UserName : Your Username is your Email ID.
Password : Your Password is first 4 letters of your last name, followed by first 4 letters of your first name.
For example:
Name:John Doe
User ID:John.Doe
Password:doejohn
Here, second employee will never be able to login to system using these instructions as it says to use ‘jack.smith’ and might end up locking another employee’s account after 4/5 invalid attempts.
Change in email notification:
We are now adding numerical extension to the email notification that is sent to employee [only in case where this numerical extension is added by system ] such as –
UserName : Your Username is your Email ID followed by number “4321”.
Password : Your Password is first 4 letters of your last name, followed by first 4 letters of your first name.
For example:
Name:John Doe
User ID:John.Doe4321
Password:doejohn
- relates to
-
NF-1606 User ID mentioned in email notification is not correct when user id generation criterion is set to [X] digit of SSN
-
- Closed
-