in reply to login page
(Surely you wouldn't consider saying something like "the password was not 6 characters as expected and had the wrong character in the third and fifth positions..." -- the more information you provide, the more you jeopardize your own security.)
If either the user name or password is incorrect, you should just be responding with "Invalid login attempt, please try again." Don't say anything more about what, in particular, was invalid. If either or both fields are empty, you can say "You need to fill in both user name and password." That's it.
So you really have only two distinct responses to worry about, and the different conditions to trigger one vs. the other should be pretty simple to work out.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: login page
by mikeB (Friar) on Dec 19, 2006 at 15:28 UTC |